Executive brief
Zoho ZeptoMail is a WordPress plugin used to send transactional emails through Zoho's delivery service. A security flaw in the plugin's access controls could allow a user with low-level account access (such as a subscriber) to perform actions they should not be authorized to do. While the impact is considered low, it could potentially lead to service disruptions or unauthorized configuration changes.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Zoho ZeptoMail plugin for WordPress through version 3.2.9. The flaw allows an authenticated attacker with 'Subscriber' or higher privileges to bypass intended access control security levels due to insufficient validation of user permissions on certain functions. An attacker can exploit this to execute actions that should be restricted to administrators, potentially impacting the availability of the email service. The issue is addressed in version 3.3.0.
Affected products
- Zoho ZeptoMail (WordPress plugin) up to 3.2.9
Timeline
- 2025-12-09: other: Reported by Legion Hunter
- 2026-02-20: disclosed
- 2026-05-21: patched: Version 3.3.0 released
- 2026-05-21: advisory