WordPress Plugin Vulnerabilities

ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute

Description

The plugin does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

Proof of Concept

Affects Plugins

Fixed in 1.2.0

References

Classification

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-07-16 (about 1 month ago)
Added
2026-07-16 (about 1 month ago)
Last Updated
2026-08-19 (about 13 hours ago)

Other