MEDIUM 5.3 NVD
CVE-2026-18437
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
References
- https://plugins.trac.wordpress.org/browser/mailerpress/trunk/src/Api/Contacts.php#L801
- https://plugins.trac.wordpress.org/browser/mailerpress/trunk/src/Api/Contacts.php#L847
- https://www.wordfence.com/threat-intel/vulnerabilities/id/159d031b-0362-4625-9d98-3908401c
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-07-31 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.