PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14919 ShopMonitor.io CVE debrief

The ShopMonitor.io WordPress plugin before 1.2.0 has a critical vulnerability allowing unauthenticated attackers to redirect outgoing emails, potentially leading to administrator account takeover. This issue arises from the plugin's improper restriction of its email-rerouting test mode, which can be exploited by manipulating client-supplied request headers. As a result, attackers can control the destination of emails, including the WordPress administrator password-reset email. The vulnerability is rated critical with a CVSS score of 9.8. WordPress administrators using the ShopMonitor.io plugin should assess their exposure and apply vendor remediation promptly to prevent potential administrator account takeovers.

Vendor
ShopMonitor.io
Product
ShopMonitor.io WordPress plugin
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-31
Original CVE updated
2026-07-31
Advisory published
2026-07-31
Advisory updated
2026-07-31

Who should care

WordPress administrators using the ShopMonitor.io plugin, security teams monitoring for email-based attacks, and IT personnel responsible for email security and vulnerability management should be aware of this critical vulnerability. They should assess their exposure, verify and apply vendor remediation, and implement compensating controls to prevent potential administrator account takeovers.

Technical summary

The ShopMonitor.io WordPress plugin before version 1.2.0 does not properly restrict its email-rerouting test mode, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control. This could lead to administrator account takeover. The vulnerability is critical, with a CVSS score of 9.8, and affects WordPress administrators using the ShopMonitor.io plugin. Security teams should prioritize monitoring for email-based attacks and implement compensating controls for email security.

Defensive priority

High priority due to potential for administrator account takeover

Recommended defensive actions

  • Verify and apply vendor remediation for ShopMonitor.io WordPress plugin
  • Restrict email-rerouting test mode access
  • Monitor for suspicious email activity
  • Implement compensating controls for email security
  • Review and update email security policies
  • Conduct regular security audits for email-related vulnerabilities
  • Track and analyze email security-related incidents

Evidence notes

The evidence for this CVE is limited, primarily based on official records indicating a critical vulnerability in the ShopMonitor.io WordPress plugin before version 1.2.0. Further verification is needed to confirm affected scope and severity. Defenders should verify the official CVE record and NVD details for accurate information and assess their exposure. Additional review of source references and security advisories may provide more context.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:25.963Z and has not been modified since then.