CVE-2026-14919 PUBLISHED

ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute

Assigner: WPScan
Reserved: 07.07.2026 Published: 31.07.2026 Updated: 31.07.2026

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.

Product Status

Vendor Unknown
Product ShopMonitor.io
Versions Default: unaffected
  • affected from 0 to 1.2.0 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE