Stats Digest Feeds
← Back to all CVEs

CVE-2026-18437

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Jul 31, 2026
Vendor unknown

Description

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.

References