CVE-2026-13156

MEDIUM

MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-13156. PoCs published by MinhHK68.

AI-analyzed exploit summary This repository contains a functional proof-of-concept (PoC) exploit for CVE-2026-13156, a Cross-Site Request Forgery (CSRF) vulnerability in the MailerSend WordPress plugin (< 1.0.8). The exploit demonstrates how an attacker can craft a malicious HTML page to delete SMTP configurations and deactivate the plugin when visited by an authenticated WordPress administrator, leading to denial of service for email workflows.

Description

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.

Exploits (1)

github WORKING POC
by MinhHK68 · poc
https://github.com/MinhHK68/CVE-2026-13156

This repository contains a functional proof-of-concept (PoC) exploit for CVE-2026-13156, a Cross-Site Request Forgery (CSRF) vulnerability in the MailerSend WordPress plugin (< 1.0.8). The exploit demonstrates how an attacker can craft a malicious HTML page to delete SMTP configurations and deactivate the plugin when visited by an authenticated WordPress administrator, leading to denial of service for email workflows.

Classification
Working Poc 98%
Attack Type
Csrf
Complexity
Trivial
Reliability
Reliable
Target: MailerSend – Official SMTP Integration WordPress plugin < 1.0.8
Auth required
Prerequisites: Authenticated WordPress administrator session · Victim must visit attacker-controlled webpage while logged in
mistral-large-3 · analyzed Jul 21, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/595e653d-0904-43cf-8e61-d684599de11b/

Scores

CVSS v3 5.4
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
None/MailerSend < 1.0.8
Published Jul 20, 2026
Tracked Since Jul 20, 2026