CVE-2026-15426

8.8

Acyba · AcyMailing

The AcyMailing plugin for WordPress is vulnerable to an authorization bypass flaw that allows low-privileged users to perform actions exceeding their intended permissions.

Executive summary

An authorization bypass vulnerability in the AcyMailing WordPress plugin allows authenticated low-privileged users to perform unauthorized actions, potentially leading to full control over plugin features.

Vulnerability

This is an improper privilege management vulnerability (CWE-269) that permits authenticated users with low privileges to bypass authorization checks, enabling them to execute sensitive functions within the plugin.

Business impact

By exploiting this flaw, an attacker could manipulate marketing automation settings, access subscriber data, or potentially alter newsletter content. With a CVSS score of 8.8, the vulnerability poses a substantial risk of unauthorized data access and integrity loss within the WordPress environment.

Remediation

Immediate Action: Update the AcyMailing plugin to version 11.0.0 or later immediately.

Proactive Monitoring: Review audit logs for unexpected configuration changes or unauthorized access to the AcyMailing dashboard by non-administrative users.

Compensating Controls: If an immediate update is not feasible, restrict access to the WordPress administrative dashboard and plugin settings via IP-based access control or WAF rules.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Given the ease of exploitation for authenticated users, administrators must treat this as a critical update. Verify your plugin version and apply the patch to version 11.0.0 immediately to prevent unauthorized privilege escalation.