Unauthorized Access Vulnerability in MailPress Plugin for WordPress
CVE-2026-18436
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 July 2026
What is CVE-2026-18436?
The MailPress plugin for WordPress is susceptible to unauthorized access due to a flaw in the campaign revision-restore REST endpoint. In versions up to and including 1.5.0, the endpoint was registered without a permissionCallback, allowing unauthenticated attackers to execute the restoreRevision() handler. This oversight enables unauthorized users to overwrite a campaign's content by restoring any prior revision, posing significant risks of content manipulation and misinformation.
Affected Version(s)
MailerPress – Newsletter, email marketing & AI automation 0 <= 1.5.0