Unauthorized Access in MailerPress Email Marketing Plugin for WordPress
CVE-2026-18437
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 July 2026
What is CVE-2026-18437?
The MailerPress plugin for WordPress has a flaw that allows unauthorized users to access and modify contact details through the mailerpress/v1/contact endpoint. This vulnerability arises from a missing capability check, enabling unauthenticated attackers to exploit this endpoint. All versions prior to and including 1.5.0 are susceptible, which poses a significant risk to users relying on the plugin for email marketing and automation. It is crucial for administrators to update to a secure version to protect their contact data and maintain the integrity of their email marketing efforts.
Affected Version(s)
MailerPress – Newsletter, email marketing & AI automation 0 <= 1.5.0