← back
CVE-2026-13156mediumCWE-352

MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 5.4epss 0.1%
from disclosure to weapon1 days
Published on NVDJul 20
1st PoC+1d
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Affected products
Unknown · MailerSend
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.