Junglewise Threat Intelligence

CVE-2026-2515: Hostinger Reach WordPress plugin missing authorization in handle_ajax_action

CVE-2026-2515 · Severity: medium · CVSS 5.3 · Published 2026-05-13

Executive brief

The Hostinger Reach plugin for WordPress, which provides AI-powered email marketing tools, contains a security flaw that allows low-level users to modify internal settings. Specifically, an attacker with a basic subscriber account could change the plugin's API key if the site has not yet been fully configured. This could allow an unauthorized party to hijack the connection between the website and the marketing service, potentially disrupting email operations or redirecting marketing data.

Technical details

The Hostinger Reach plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check in the 'handle_ajax_action' function. This flaw allows authenticated attackers with Subscriber-level permissions or higher to execute the 'hostinger_reach_connection_notice_action' AJAX action. By exploiting this, an attacker can update the API key value stored in the WordPress database. Exploitation is limited to instances where the plugin is not yet connected to a site and no API key currently exists. The issue is addressed in versions following 1.3.8.

Affected products

  • Hostinger Hostinger Reach – AI-Powered Email Marketing for WordPress up to, and including, 1.3.8

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory

References