Description
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.
Published: 2026-07-31
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ShopMonitor.io WordPress plugin version prior to 1.2.0 contains a flaw that allows an unauthenticated attacker to manipulate request headers and invoke a test mode email‑rerouting function. By redirecting the password‑reset email to an address controlled by the attacker, the adversary can gain control of the WordPress administrator account without needing valid credentials. This privilege escalation results in full administrative access to the site.

Affected Systems

WordPress sites running the ShopMonitor.io plugin before version 1.2.0. The vendor is listed as Unknown:ShopMonitor.io. Any installation of the plugin that has not migrated to 1.2.0 or later is vulnerable.

Risk and Exploitability

The vulnerability’s CVSS score of 9.8 signals critical severity, indicating that an attacker can fully compromise an administrator account. The EPSS score is below 1%, suggesting a low current exploitation probability, but the combination of an easy‑to‑exploit HTTP request and the high severity means the risk remains significant. Exploitation requires only the ability to craft request headers to trigger the plugin’s email‑rerouting test mode; no authentication is needed. Once the password‑reset email is redirected to an attacker‑controlled address, the attacker can reset the administrator password and gain full site control. The vulnerability is not listed in CISA’s KEV catalog, but the severe impact warrants immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 11:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ShopMonitor.io to version 1.2.0 or later.
  • If an update is not yet available, disable the email‑rerouting test mode feature or remove the plugin until a fix is released.
  • Enable multi‑factor authentication and enforce strong passwords for WordPress administrator accounts to mitigate credential compromise.

Generated by OpenCVE AI on August 4, 2026 at 11:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 31 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.
Title ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-31T16:38:27.612Z

Reserved: 2026-07-07T07:56:11.961Z

Link: CVE-2026-14919

cve-icon Vulnrichment

Updated: 2026-07-31T16:38:13.659Z

cve-icon NVD

Status : Received

Published: 2026-07-31T07:16:25.963

Modified: 2026-07-31T17:16:32.863

Link: CVE-2026-14919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T11:30:07Z

Weaknesses