PT-2026-34306 · WordPress · Sendmachine

Nabil Irawan

·

Published

2026-04-22

·

Updated

2026-05-01

·

CVE-2026-6235

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sendmachine for WordPress versions prior to 1.0.21
Description An authorization bypass exists via the manage admin requests() function because the plugin fails to properly verify if a user is authorized to perform an action. This allows unauthenticated attackers to overwrite the SMTP configuration, enabling the interception of all outbound emails from the site, including password reset emails.
Recommendations Update to a version later than 1.0.20. As a temporary workaround, consider restricting access to the manage admin requests() function until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6235

Affected Products

Sendmachine