CVE-2026-78003 carries a CVSS 3.1 base score of 9.8 against Mailgun for WordPress, a plugin that connects WordPress sites to the Mailgun email delivery service. NVD classifies it as CWE-918 (Server-Side Request Forgery) and states the flaw affects versions up to and including 2.2.0. VulnCheck’s KEV feed reports the CVE as exploited, dated August 28, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-78003 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description traces the flaw to the plugin’s add_list() function, which accepts user-controlled array keys from the $_POST['addresses'] request parameter and passes them through sanitize_text_field() — a WordPress function meant for cleaning plain text, not for validating that a value is safe to use as part of a server-side request destination. NVD states this insufficient validation makes it possible for an unauthenticated attacker to make authenticated POST requests to any Mailgun API endpoint, using the WordPress site’s own stored Mailgun API key to authenticate those requests on the attacker’s behalf.
The stated impact goes beyond a typical SSRF’s usual “attacker can reach internal network resources” outcome: NVD states an attacker can use this access to create inbound email-forwarding routes within the site’s own Mailgun account. Because password-reset emails for the WordPress site itself may flow through that same Mailgun account, an attacker-created forwarding route can intercept those reset emails, and NVD states this chain leads to full Administrator account takeover.
Evidence and confidence
- Medium confidence — the CVSS 9.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-918 classification, the vulnerable function (add_list()), the affected-version ceiling (2.2.0), and the full attack chain through to Administrator takeover all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone. - Above-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00873, a 57.1th percentile score as of our ingestion.
No field is in conflict between our two sources. Our data carries no structured fixed-version field beyond NVD’s “through 2.2.0” affected-version statement.
Why this matters
What elevates this beyond a typical SSRF finding is the specific chain NVD describes: the vulnerability doesn’t just expose internal network resources, it weaponizes the site’s own legitimate email infrastructure against its own account-recovery mechanism. A site operator scanning only for classic SSRF impact (internal port scanning, cloud metadata endpoint access) could miss that the more direct and severe outcome here is domain-specific — abuse of the exact email-delivery path the site relies on for password resets.
Sites running Mailgun for WordPress up to and including 2.2.0 should treat this as urgent regardless of whether they’ve observed unusual Mailgun API activity, since NVD’s description indicates the attack requires no prior authentication and leaves the WordPress-side forwarding-route abuse difficult to notice without directly auditing the Mailgun account’s own routing configuration.
Frequently Asked Questions
What is CVE-2026-78003? A CVSS 9.8 Server-Side Request Forgery vulnerability (CWE-918) in the Mailgun for WordPress plugin, through version 2.2.0, allowing unauthenticated attackers to make authenticated Mailgun API requests using the site’s own API key.
Is CVE-2026-78003 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 28, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.
How does this lead to a full account takeover? NVD states an attacker can use the forged API access to create inbound email-forwarding routes in the site’s Mailgun account, which can intercept password-reset emails and lead to Administrator account takeover.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
What should site operators check? Review the Mailgun account’s own routing/forwarding configuration for any unrecognized inbound routes, in addition to updating the plugin past the affected 2.2.0 ceiling.
Severity, vector, weakness classification, vulnerable function, affected-version ceiling, and the full attack chain sourced from the National Vulnerability Database record for CVE-2026-78003. Exploitation status and the August 28, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.