Critical Vulnerability in ShopMonitor.io WordPress Plugin: CVE-2026-14919
A critical vulnerability (CVE-2026-14919, CVSS 9.8) exists in the ShopMonitor.io WordPress plugin prior to version 1.2.0. This vulnerability allows unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, potentially leading to administrator account takeover. The vulnerability is easily exploitable with a low attack complexity and no required privileges or user interaction. Immediate patching or mitigation is strongly recommended.