PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13156 MailerSend CVE debrief

The MailerSend WordPress plugin before 1.0.8 has a vulnerability that allows an attacker to trick a logged-in administrator into visiting a crafted page, resulting in the deletion of the plugin's SMTP configuration and deactivation of the plugin, breaking the site's email delivery. This vulnerability is related to the plugin's configuration-delete action, which does not perform a nonce check. As a result, an attacker can exploit this vulnerability to wipe the plugin's SMTP configuration and deactivate the plugin. The vulnerability has a medium defensive priority, and administrators of WordPress sites using the MailerSend plugin should verify that their plugin is up-to-date and consider reviewing user interactions with the plugin's configuration.

Vendor
MailerSend
Product
MailerSend WordPress plugin
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-07-20
Advisory published
2026-07-20
Advisory updated
2026-07-20

Who should care

Administrators of WordPress sites using the MailerSend plugin should verify that their plugin is up-to-date and consider reviewing user interactions with the plugin's configuration. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on their organization's WordPress sites.

Technical summary

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action, allowing an attacker to trick a logged-in administrator into visiting a crafted page that wipes the plugin's SMTP configuration and deactivates the plugin. This vulnerability can be exploited by an attacker to delete the plugin's SMTP configuration and deactivate the plugin, breaking the site's email delivery. The plugin's configuration-delete action is vulnerable to a nonce check bypass, which allows an attacker to perform unauthorized actions on the plugin's configuration.

Defensive priority

Medium

Recommended defensive actions

  • Verify that the MailerSend WordPress plugin is updated to version 1.0.8 or later.
  • Review user interactions with the plugin's configuration to prevent unauthorized changes.
  • Consider implementing additional security measures to prevent similar attacks.
  • Monitor for suspicious activity related to the plugin's configuration-delete action.
  • Perform a thorough review of the plugin's configuration and security settings.
  • Consider implementing compensating controls to prevent exploitation of the vulnerability.
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully resolved.

Evidence notes

The CVE record was published on 2026-07-20T07:16:35.687Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action, allowing an attacker to trick a logged-in administrator into visiting a crafted page that wipes the plugin's SMTP configuration and deactivates the plugin. Evidence of exploitation or affected deployments has not been confirmed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-13156 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-13156

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-13156 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13156

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.