Junglewise Threat Intelligence

CVE-2026-24547: SiteGround Email Marketing broken access control

CVE-2026-24547 · Severity: medium · CVSS 5.3 · Published 2026-06-26

Executive brief

The SiteGround Email Marketing plugin for WordPress, which helps website owners manage email campaigns and newsletters, contains a security flaw in its access control mechanisms. This vulnerability allows unauthorized individuals to perform certain actions within the plugin that should normally be restricted to administrators. While the impact is considered low, it could allow an attacker to interfere with email marketing settings or data without needing a password.

Technical details

The SiteGround Email Marketing plugin for WordPress (versions <= 1.7.5) suffers from a missing authorization check (CWE-862), classified as broken access control. This vulnerability allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The flaw likely stems from a lack of proper capability checks or nonce validation on specific AJAX or administrative hooks. An attacker can exploit this over the network without any user interaction to modify plugin settings or data. The issue is resolved in version 1.7.6.

Affected products

  • SiteGround SiteGround Email Marketing <= 1.7.5

Timeline

  • 2025-12-24: other: Reported by Nabil Irawan
  • 2026-06-25: advisory: Published by Patchstack
  • 2026-06-26: disclosed: NVD publication date

References