Sploitus

CVE-2026-13156

2 known exploits for CVE-2026-13156

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.

Affected products
Mailersend
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.1% (3th percentile)
Weakness
CWE-352
NVD status
Deferred
Published
2026-07-20
CVE-2026-13156 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-13156

Proof-of-concept code and exploit modules indexed by Sploitus