CyberRota
← Ana sayfaya dön

CVE-2026-13156

MEDIUM · CVSS 5.4 EPSS %0.10

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-20T07:16:35.687 · Çekilme zamanı: 2026-07-21T06:06:23.216117+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-13156
Severity
MEDIUM
CVSS
5.4
EPSS
%0.10
WordPress

Orijinal NVD Açıklaması

The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capability but ignores the nonce), so an attacker can trick a logged-in administrator into visiting a crafted page that wipes the MailerSend WordPress plugin before 1.0.8's SMTP configuration and deactivates the MailerSend WordPress plugin before 1.0.8, breaking the site's email delivery.