CVE-2026-14834

CVE-2026-14834: Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX

Vendor Unknown
Product Mailgun for WordPress
Published July 31, 2026
Last update July 31, 2026

CVSS base score

What the vulnerability does

01Description

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.

Key dates

02Disclosure timeline

July 31, 2026 CVE published
July 31, 2026 Record updated