CRITICAL
ShopMonitor.io
CVE published 2026-07-31
CVE-2026-14919
The ShopMonitor.io WordPress plugin before 1.2.0 has a critical vulnerability allowing unauthenticated attackers to redirect outgoing emails, potentially leading to administrator account takeover. This issue arises from the plugin's improper restriction of its email-rerouting test mode, which can be exploited by manipulating client-supplied request headers. As a result, attackers can control the destinati [truncated]