PatchSiren cyber security CVE debrief
CVE-2026-13156 MailerSend CVE debrief
The MailerSend WordPress plugin before 1.0.8 has a vulnerability that allows an attacker to trick a logged-in administrator into visiting a crafted page, resulting in the deletion of the plugin's SMTP configuration and deactivation of the plugin, breaking the site's email delivery. This vulnerability is related to the plugin's configuration-delete action, which does not perform a nonce check. As a result, an attacker can exploit this vulnerability to wipe the plugin's SMTP configuration and deactivate the plugin. The vulnerability has a medium defensive priority, and administrators of WordPress sites using the MailerSend plugin should verify that their plugin is up-to-date and consider reviewing user interactions with the plugin's configuration.
- Vendor
- MailerSend
- Product
- MailerSend WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-20
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-20
Who should care
Administrators of WordPress sites using the MailerSend plugin should verify that their plugin is up-to-date and consider reviewing user interactions with the plugin's configuration. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their organization's WordPress sites.
Technical summary
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action, allowing an attacker to trick a logged-in administrator into visiting a crafted page that wipes the plugin's SMTP configuration and deactivates the plugin. This vulnerability can be exploited by an attacker to delete the plugin's SMTP configuration and deactivate the plugin, breaking the site's email delivery. The plugin's configuration-delete action is vulnerable to a nonce check bypass, which allows an attacker to perform unauthorized actions on the plugin's configuration.
Defensive priority
Medium
Recommended defensive actions
- Verify that the MailerSend WordPress plugin is updated to version 1.0.8 or later.
- Review user interactions with the plugin's configuration to prevent unauthorized changes.
- Consider implementing additional security measures to prevent similar attacks.
- Monitor for suspicious activity related to the plugin's configuration-delete action.
- Perform a thorough review of the plugin's configuration and security settings.
- Consider implementing compensating controls to prevent exploitation of the vulnerability.
- Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved.
Evidence notes
The CVE record was published on 2026-07-20T07:16:35.687Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action, allowing an attacker to trick a logged-in administrator into visiting a crafted page that wipes the plugin's SMTP configuration and deactivates the plugin. Evidence of exploitation or affected deployments has not been confirmed.
Official resources
-
CVE-2026-13156 CVE record
CVE.org
-
CVE-2026-13156 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T07:16:35.687Z and has not been modified since then.