Review
MailerSend
CVE published 2026-07-20
CVE-2026-13156
The MailerSend WordPress plugin before 1.0.8 has a vulnerability that allows an attacker to trick a logged-in administrator into visiting a crafted page, resulting in the deletion of the plugin's SMTP configuration and deactivation of the plugin, breaking the site's email delivery. This vulnerability is related to the plugin's configuration-delete action, which does not perform a nonce check. As a result, [truncated]