PatchSiren

ShopMonitor.io CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL ShopMonitor.io CVE published 2026-07-31

CVE-2026-14919

The ShopMonitor.io WordPress plugin before 1.2.0 has a critical vulnerability allowing unauthenticated attackers to redirect outgoing emails, potentially leading to administrator account takeover. This issue arises from the plugin's improper restriction of its email-rerouting test mode, which can be exploited by manipulating client-supplied request headers. As a result, attackers can control the destinati [truncated]