CyberRota
← Ana sayfaya dön

CVE-2026-6963

HIGH · CVSS 8.8 EPSS %0.02

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-02T05:16:01.250 · Çekilme zamanı: 2026-06-01T00:00:18.244317+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-6963
Severity
HIGH
CVSS
8.8
EPSS
%0.02
WordPress

Orijinal NVD Açıklaması

The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update SMTP settings and redirect mail which can be used for privilege escalation by triggering a password reset email and using that to access and administrator's account.