CVE-2026-13156: CWE-352 Cross-Site Request Forgery (CSRF) in MailerSend
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.
AI Analysis
Technical Summary
The MailerSend WordPress plugin prior to version 1.0.8 does not perform a nonce check on its configuration-delete action, although it verifies the manage_options capability. This omission enables a CSRF attack whereby an attacker can cause a logged-in administrator to unknowingly trigger the deletion of the plugin's SMTP configuration and deactivate the plugin, resulting in broken email functionality.
Potential Impact
Successful exploitation results in the removal of SMTP configuration settings and deactivation of the MailerSend plugin, causing email delivery failures on the affected WordPress site. This can disrupt critical communications dependent on the site's email capabilities.
Mitigation Recommendations
No official fix or patch is currently confirmed. Users should upgrade to MailerSend version 1.0.8 or later once available, as this version presumably addresses the nonce verification issue. Until then, administrators should avoid visiting untrusted or suspicious web pages while logged into WordPress with administrative privileges. Monitor the vendor advisory for updates on remediation.
CVE-2026-13156: CWE-352 Cross-Site Request Forgery (CSRF) in MailerSend
Description
The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.
CVSS v3.1
Score 5.4medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The MailerSend WordPress plugin prior to version 1.0.8 does not perform a nonce check on its configuration-delete action, although it verifies the manage_options capability. This omission enables a CSRF attack whereby an attacker can cause a logged-in administrator to unknowingly trigger the deletion of the plugin's SMTP configuration and deactivate the plugin, resulting in broken email functionality.
Potential Impact
Successful exploitation results in the removal of SMTP configuration settings and deactivation of the MailerSend plugin, causing email delivery failures on the affected WordPress site. This can disrupt critical communications dependent on the site's email capabilities.
Mitigation Recommendations
No official fix or patch is currently confirmed. Users should upgrade to MailerSend version 1.0.8 or later once available, as this version presumably addresses the nonce verification issue. Until then, administrators should avoid visiting untrusted or suspicious web pages while logged into WordPress with administrative privileges. Monitor the vendor advisory for updates on remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-24T12:02:09.353Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5dca642a4a8d598994e615
Added to database: 07/20/2026, 07:12:36 UTC
Last enriched: 07/20/2026, 07:27:11 UTC
Last updated: 07/21/2026, 05:26:42 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.