PatchSiren

sendmachine CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL sendmachine CVE published 2026-04-22

CVE-2026-6235

The Sendmachine for WordPress plugin is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This allows unauthenticated attackers to overwrite the plugin's SMTP configuration, potentially intercepting all outbound emails from the site. The vulnerability has a high CVSS score of 9.8 and is considered critical. Affected WordPress site adm [truncated]