The ShopMonitor.io WordPress plugin before 1.2.0 does...
Critical severity
Unreviewed
Published
Jul 31, 2026
to the GitHub Advisory Database
•
Updated Jul 31, 2026
Description
Published by the National Vulnerability Database
Jul 31, 2026
Published to the GitHub Advisory Database
Jul 31, 2026
Last updated
Jul 31, 2026
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.
References