CVE-2026-13156
MEDIUMMailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-13156. PoCs published by MinhHK68.
AI-analyzed exploit summary This repository contains a functional proof-of-concept (PoC) exploit for CVE-2026-13156, a Cross-Site Request Forgery (CSRF) vulnerability in the MailerSend WordPress plugin (< 1.0.8). The exploit demonstrates how an attacker can craft a malicious HTML page to delete SMTP configurations and deactivate the plugin when visited by an authenticated WordPress administrator, leading to denial of service for email workflows.
Description
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.
Exploits (1)
This repository contains a functional proof-of-concept (PoC) exploit for CVE-2026-13156, a Cross-Site Request Forgery (CSRF) vulnerability in the MailerSend WordPress plugin (< 1.0.8). The exploit demonstrates how an attacker can craft a malicious HTML page to delete SMTP configurations and deactivate the plugin when visited by an authenticated WordPress administrator, leading to denial of service for email workflows.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L