Executive brief
A security vulnerability exists in the Omnisend Email Marketing plugin for WooCommerce, which is used by online stores to manage customer communications. This flaw allows unauthorized individuals to bypass security checks and potentially perform actions reserved for administrators. If exploited, an attacker could gain administrative control over the website, leading to data theft or complete site takeover.
Technical details
The Email Marketing for WooCommerce by Omnisend plugin (versions 1.18.0 and earlier) contains a broken authentication vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The flaw allows an unauthenticated remote attacker to bypass security protocols and execute functions that should require high-level privileges. According to the advisory, this bypass can be leveraged to gain administrative access to the WordPress site. The vulnerability is exploitable over the network without user interaction. A fix is available in version 1.18.1.
Affected products
- Omnisend Email Marketing for WooCommerce by Omnisend <= 1.18.0
Timeline
- 2026-04-10: other: Vulnerability reported by researcher 0xzenko
- 2026-05-10: advisory: Patchstack published advisory and mitigation rules
- 2026-06-15: disclosed: CVE published to NVD
- 2026-05-10: patched: Version 1.18.1 released to address the issue