CRITICAL
sendmachine
CVE published 2026-04-22
CVE-2026-6235
The Sendmachine for WordPress plugin is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This allows unauthenticated attackers to overwrite the plugin's SMTP configuration, potentially intercepting all outbound emails from the site. The vulnerability has a high CVSS score of 9.8 and is considered critical. Affected WordPress site adm [truncated]