PT-2026-34306 · WordPress · Sendmachine

·

CVE-2026-6235

·

Published

2026-04-21

·

Updated

2026-08-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sendmachine for WordPress versions prior to 1.0.21
Description An authorization bypass exists due to improper verification of user permissions within the manage admin requests() function. This flaw allows unauthenticated attackers to overwrite the SMTP configuration of the plugin, enabling the interception of all outbound emails from the site, including password reset notifications.
Recommendations Update the plugin to a version later than 1.0.20. As a temporary workaround, consider disabling the manage admin requests() function until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6235

Affected Products

Sendmachine