๐Ÿ” CVE Alert

CVE-2026-14919

UNKNOWN 0.0

ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

Vendor unknown
Product shopmonitor.io
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for unknown shopmonitor.io

Be the first to know when new unknown vulnerabilities affecting unknown shopmonitor.io are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ShopMonitor.io
0 < 1.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/6d929535-9757-44ae-8c58-682f1eb89785/

Credits

Pedro Pinho WPScan