Description
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
Published: 2026-07-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MailerPress WordPress plugin contains a missing capability check on the 'mailerpress/v1/contact' API endpoint, allowing anyone to send contact update requests without authentication. This flaw is categorized as CWE-862 (Missing Authorization). An attacker can modify any contact’s details, potentially altering email lists, personal data, or marketing configurations, compromising the integrity of the data stored by the site.

Affected Systems

The vulnerability affects the MailerPress – Newsletter, email marketing & AI automation plugin for WordPress in all releases up to and including version 1.5.0. Users running these versions are at risk; only versions newer than 1.5.0 contain the fix.

Risk and Exploitability

With a CVSS score of 5.3 and an EPSS score of less than 1%, the flaw presents a moderate severity and a low but non‑zero likelihood of exploitation. It is not listed in the CISA KEV catalog. Attackers would exploit the flaw by issuing unauthenticated HTTP requests to the vulnerable endpoint, potentially immediately after discovering it in the open source code. Although public exploits are not yet documented, the vulnerability could be leveraged to silently modify user data or inject malicious content into contact records.

Generated by OpenCVE AI on August 2, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MailerPress plugin to version 1.5.1 or later.
  • If an immediate upgrade is not possible, apply a local patch that adds an authorization check (for example, validating that the current user has administrator capabilities) before allowing updates on the /mailerpress/v1/contact endpoint.
  • Configure your web application firewall or server rules to block unauthenticated requests to the /mailerpress/v1/contact API endpoint until the plugin is updated.

Generated by OpenCVE AI on August 2, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mailerpress
Mailerpress mailerpress – Newsletter, Email Marketing & Ai Automation
Wordpress
Wordpress wordpress
Vendors & Products Mailerpress
Mailerpress mailerpress – Newsletter, Email Marketing & Ai Automation
Wordpress
Wordpress wordpress

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
Title MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mailerpress Mailerpress – Newsletter, Email Marketing & Ai Automation
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-31T14:50:17.110Z

Reserved: 2026-07-30T20:21:38.396Z

Link: CVE-2026-18437

cve-icon Vulnrichment

Updated: 2026-07-31T14:50:13.812Z

cve-icon NVD

Status : Deferred

Published: 2026-07-31T10:16:45.157

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:33:01Z

Weaknesses