WordPress Plugin Vulnerabilities

ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute

Description

The plugin does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

Proof of Concept

Affects Plugins

Fixed in 1.2.0

References

Classification

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-07-16 (about 15 days ago)
Added
2026-07-16 (about 14 days ago)
Last Updated
2026-07-29 (about 1 day ago)

Other