SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14919

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The ShopMonitor.io WordPress plugin prior to version 1.2.0 is vulnerable due to inadequate restrictions on its email-rerouting test mode, which can be exploited by unauthenticated attackers using manipulated request headers. This flaw allows attackers to redirect sensitive outgoing emails, such as password-reset links for the WordPress administrator account, potentially leading to full account takeover. WordPress site administrators and those using the affected plugin should prioritize immediate updates to mitigate this critical vulnerability.

CVE
CVE-2026-14919
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%
WordPress

Original NVD Description

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.