Executive brief
AcyMailing is a WordPress plugin that handles newsletter distribution and email marketing automation. A flaw allows authenticated subscribers to modify password-reset email templates, redirecting password-reset links for any user—including administrators—to attacker-controlled addresses. This enables account takeover if the site has configured WordPress to route emails through AcyMailing.
Technical details
The vulnerability is an authorization bypass in the plugin's notification template handling, specifically affecting the acy_notification_cms template. The plugin fails to properly verify that an authenticated user has permission to modify email notification settings. An attacker with subscriber-level access or above can overwrite the BCC field of the password-reset notification template, causing all subsequent password-reset emails—including those for administrator accounts—to be silently copied to an attacker-controlled email address. Exploitation requires the site administrator to have enabled "Send website emails with AcyMailing," which routes WordPress core notifications through the plugin's email system. The attacker can then intercept password-reset links and take over accounts.
Affected products
- AcyMailing AcyMailing up to and including 10.11.1
Timeline
- 2026-08-11: disclosed