CVE-2026-14919
ShopMonitor.io · ShopMonitor.io WordPress Plugin
A critical authentication bypass in the ShopMonitor.io WordPress plugin allows unauthenticated attackers to hijack administrator accounts via email redirection.
Executive summary
The ShopMonitor.io WordPress plugin contains an authentication bypass vulnerability that permits attackers to perform full account takeover of the WordPress administrator.
Vulnerability
The plugin fails to perform proper capability checks on its email-rerouting test mode. An unauthenticated attacker can manipulate request headers to satisfy internal checks, allowing them to redirect critical emails, such as password reset links, to an attacker-controlled address.
Business impact
This vulnerability enables total account takeover of the WordPress administrator, leading to full site compromise and potential data exfiltration. Given the critical 9.8 CVSS score, the impact is severe, as it bypasses the primary authentication mechanism of the entire WordPress installation.
Remediation
Immediate Action: Update the ShopMonitor.io plugin to version 1.2.0 or higher immediately.
Proactive Monitoring: Review WordPress user account logs for unexpected password reset requests or unauthorized account modifications.
Compensating Controls: If an update cannot be applied immediately, deactivate the ShopMonitor.io plugin entirely to remove the attack vector.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a direct threat to the integrity of the WordPress site. Administrators must verify their plugin version and apply the update to 1.2.0 immediately, or deactivate the plugin if the update is not currently feasible, to prevent unauthorized account takeovers.