PatchDay Alert

CVE

CVE-2026-6235

0field notes · 1digest CVSS 9.8


Daily digests

The Sendmachine for WordPress plugin doesn't check whether the caller is actually authorized when handling admin requests. An unauthenticated attacker can overwrite your SMTP configuration, rerouting all outbound email through a server they control. That includes password reset emails, which means full site takeover is one "forgot password" click away.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.