Junglewise Threat Intelligence

CVE-2026-5200: Acyba AcyMailing missing authorization in WordPress plugin

CVE-2026-5200 · Severity: high · CVSS 8.8 · Published 2026-05-20

Technologies: Acyba AcyMailing. Vendors: Acyba.

Executive brief

AcyMailing, a popular WordPress plugin used for managing newsletters and marketing automation, contains a security flaw that allows low-level users to perform administrative actions. An attacker with a basic subscriber account could modify the plugin's settings or export sensitive security keys. This can ultimately lead to a full takeover of the website's administrator account if the attacker knows the admin's email address.

Technical details

The AcyMailing plugin for WordPress (up to version 10.8.2) suffers from a missing authorization vulnerability (CWE-862) due to insufficient permission checks on certain plugin functions. Authenticated attackers with subscriber-level privileges or higher can exploit this to modify privileged configuration settings and export subscriber secret keys. By chaining these capabilities, an attacker who knows a target administrator's email address can achieve a full account takeover. The vulnerability is addressed in versions following 10.8.2.

Affected products

  • Acyba AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress up to, and including, 10.8.2

Timeline

  • 2026-05-20: disclosed: CVE published by Wordfence and NVD

References

Related threats