Junglewise Threat Intelligence

CVE-2026-57410: MailerPress Team MailerPress privilege escalation

CVE-2026-57410 · Severity: high · CVSS 8.8 · Published 2026-07-13

Executive brief

MailerPress, a WordPress plugin used for managing email communications, contains a security flaw that allows users with low-level access to gain higher administrative privileges. If exploited, an attacker could take full control of the website, potentially leading to data theft, site defacement, or the installation of malicious software. This vulnerability is particularly dangerous as it can be targeted in automated mass-exploit campaigns.

Technical details

An incorrect privilege assignment vulnerability (CWE-266) exists in the MailerPress plugin for WordPress through version 2.0.2. The flaw allows an authenticated attacker with low-level privileges (such as a Contributor) to escalate their permissions to a higher level, potentially reaching administrative status. The attack is reachable over the network and does not require user interaction. The issue is resolved in version 2.0.3.

Affected products

  • MailerPress Team MailerPress <= 2.0.2

Timeline

  • 2026-05-05: disclosed: Reported by anhcd05 to Patchstack
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE-2026-57410
  • 2026-07-13: patched: Version 2.0.3 confirmed as patched version

References