CVE-2026-5200
8.8Acyba · AcyMailing
A missing authorization vulnerability in the AcyMailing WordPress plugin allows authenticated users to perform unauthorized actions.
Executive summary
A critical missing authorization flaw in the AcyMailing WordPress plugin could allow authenticated users to perform unauthorized actions, potentially leading to full site compromise.
Vulnerability
The plugin suffers from a missing authorization vulnerability (CWE-862) that permits authenticated users with low privileges to perform functions reserved for higher-privileged accounts. The CVSS vector indicates that while the attacker must be authenticated, they can perform actions with significant impact on confidentiality, integrity, and availability.
Business impact
The vulnerability allows for unauthorized administrative actions within the marketing automation platform, which could lead to the exposure of sensitive subscriber data or the manipulation of newsletter content. With a CVSS score of 8.8, this represents a significant risk to site integrity and organizational reputation, as it could be leveraged to distribute malicious content to the entire subscriber base.
Remediation
Immediate Action: Update the AcyMailing plugin to version 10.9.0 or later immediately.
Proactive Monitoring: Review administrative access logs for suspicious account activity or unauthorized changes to marketing campaigns and subscriber lists.
Compensating Controls: Utilize a Web Application Firewall (WAF) to detect and block requests that attempt to access restricted plugin functions without proper authorization.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The risk posed by this vulnerability is high, particularly for organizations managing large subscriber lists. Administrators must prioritize updating the AcyMailing plugin to version 10.9.0 to close the authorization gap and prevent potential data exposure or unauthorized marketing activities.