Skip to content
WP Hack FixEst. 2005

Security news

Mailgun for WordPress: an SSRF flaw that can reroute your password-reset emails

Published · Disclosed August 22, 2026 · Reviewed by Adam Taylor

PluginVulnerableFixed in
Mailgun for WordPress<= 2.2.02.2.1

If your site sends mail through Mailgun, there’s a flaw worth checking for, even though it’s a few weeks old. It doesn’t touch your site’s own database or files. It touches your mail.

Mailgun for WordPress, used on more than 80,000 sites, had a flaw scored 9.8 out of 10. It was fixed in version 2.2.1, with a further hardening release in 2.2.2.

Am I affected?

You’re affected if your site runs Mailgun for WordPress 2.2.0 or earlier. Check the version under Plugins in your dashboard. No special configuration is needed to be exposed, and no login is needed to exploit it.

What an attacker could do

The plugin builds a request to the Mailgun API from data it receives in a form submission, and it didn’t check that data closely enough. An attacker could use that gap to make your site, using your own Mailgun API key, create a mail routing rule at Mailgun.

That rule can tell Mailgun to forward a copy of incoming mail to an address the attacker controls, including a password-reset email meant for one of your site’s users. If that user is an administrator, intercepting one reset email is enough to take over their account, and from there, the site.

Nothing about this touches WordPress logins, files, or the database directly. It works entirely through your mail configuration, which is why updating the plugin doesn’t undo a routing rule an attacker already created.

What to do

  1. Update Mailgun for WordPress to 2.2.2. Plugins → Update. This closes the hole.
  2. Log into your Mailgun account directly (not through WordPress) and check Sending → Routes for any rule you don’t recognize, especially one forwarding mail to an address that isn’t yours.
  3. Delete any routing rule you didn’t create. The plugin update stops new ones; it doesn’t remove existing ones.
  4. If you find a rule you didn’t set up, check whether any password-reset or account emails went out during the time it existed, and treat the accounts involved as potentially compromised. Get the site checked properly.

There’s no sign this has been exploited widely, but it’s been public since late August, long enough for scanning to catch up to it. If you haven’t checked your Mailgun routes since then, it’s worth five minutes.

On a Protect plan? Plugin updates are part of what we do, so this one is covered. Ask us to check your Mailgun routes too if you’re not sure how.

Worried your site's already been hit?

If something looks wrong, we'll check it and clean it up. If we can't fix it, you don't pay.

We reply within 1 business day (Mon–Fri, 9–5 ET)