Executive brief
AcyMailing, a popular WordPress plugin used for managing newsletters and marketing automation, contains a security flaw that allows low-level users to perform administrative actions. An attacker with a basic subscriber account could modify the plugin's settings or export sensitive security keys. This can ultimately lead to a full takeover of the website's administrator account if the attacker knows the admin's email address.
Technical details
The AcyMailing plugin for WordPress (up to version 10.8.2) suffers from a missing authorization vulnerability (CWE-862) due to insufficient permission checks on certain plugin functions. Authenticated attackers with subscriber-level privileges or higher can exploit this to modify privileged configuration settings and export subscriber secret keys. By chaining these capabilities, an attacker who knows a target administrator's email address can achieve a full account takeover. The vulnerability is addressed in versions following 10.8.2.
Affected products
- Acyba AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress up to, and including, 10.8.2
Timeline
- 2026-05-20: disclosed: CVE published by Wordfence and NVD