What is CVE-2026-14919?
This vulnerability exists in the ShopMonitor.io WordPress plugin before version 1.2.0, where the email-rerouting test mode is not properly restricted behind a trusted-source check that can be satisfied using client-supplied request headers. An unauthenticated attacker can redirect outgoing emails, including the WordPress admin's. Updating the plugin to version 1.2.0 is recommended.
Azərbaycanca: Bu boşluq ShopMonitor.io WordPress plagininin 1.2.0-dan əvvəlki versiyalarında email yönləndirmə test rejiminin düzgün məhdudlaşdırılmaması ilə bağlıdır. Etibarlı mənbə yoxlaması müştəri tərəfindən təqdim olunan sorğu başlıqları ilə keçilə bildiyi üçün autentifikasiya olunmamış hücumçu WordPress admin də daxil olmaqla gedən emailləri yönləndirə bilər. Plaginin ən son 1.2.0 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the ShopMonitor.io plugin are affected by CVE-2026-14919?
CVE-2026-14919 affects the ShopMonitor.io WordPress plugin before version 1.2.0.
What can an unauthenticated attacker do by exploiting CVE-2026-14919?
An unauthenticated attacker can redirect outgoing emails, including the WordPress admin's.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.