Executive brief
AcyMailing, a popular newsletter and marketing automation plugin for WordPress, contains a security flaw that allows users with contributor-level access or higher to inject malicious scripts into website pages. These scripts will automatically run in the browser of any visitor who views the affected page. This could lead to unauthorized actions being performed on behalf of site administrators or the theft of sensitive session information.
Technical details
The AcyMailing plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'alignment' attribute. This vulnerability exists in all versions up to and including 10.10.2. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting malicious JavaScript into a page. Because the input is stored on the server and later rendered without proper neutralization, the script executes in the context of any user (including administrators) who visits the compromised page. This can lead to session hijacking or unauthorized administrative actions.
Affected products
- acyba AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Up to and including 10.10.2
Timeline
- 2026-07-09: disclosed: CVE published to the NVD dataset
References
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/WpInit/Gutenberg.php
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/WpInit/Gutenberg.php
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Core/wordpress/form.php
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Core/wordpress/form.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3597432%40acymailing&new=3597432%40acymailing
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4fd76fbc-22df-4071-a2ae-9c9ac9cdbc57?source=cve