top of page
perceptive_background_267k.jpg

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and inc…

Published:

21 april 2026 om 22:00:00

Alert date:

22 april 2026 om 22:11:22

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

The Sendmachine for WordPress plugin contains an authorization bypass vulnerability in the 'manage_admin_requests' function affecting all versions up to 1.0.20. The vulnerability allows unauthenticated attackers to overwrite SMTP configuration settings due to improper user authorization verification. This can enable attackers to intercept all outbound emails from the affected WordPress site, including sensitive password reset emails. The vulnerability poses a high risk as it requires no authentication and can lead to email interception and potential account takeover scenarios.

Technical details

Mitigation steps:

Affected products:

Sendmachine for WordPress plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page