Junglewise Threat Intelligence

CVE-2026-57632: Omnisend Email Marketing for WooCommerce broken access control

CVE-2026-57632 · Severity: medium · CVSS 5.4 · Published 2026-06-26

Executive brief

The Omnisend Email Marketing plugin for WooCommerce, which helps businesses manage customer email campaigns and newsletters, contains a security flaw in its access control mechanisms. This vulnerability allows logged-in users with low-level 'Subscriber' permissions to perform actions they should not be authorized to do. While the impact is considered moderate, it could allow unauthorized changes to plugin settings or data, potentially disrupting marketing operations.

Technical details

A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Email Marketing for WooCommerce by Omnisend plugin for WordPress in versions up to and including 1.19.0. The flaw stems from insufficient authorization checks on certain plugin functions, allowing an authenticated attacker with Subscriber-level privileges to execute actions intended for higher-privileged users. The attack is reachable over the network without user interaction. The vulnerability was addressed in version 1.19.1 by implementing proper permission checks.

Affected products

  • Omnisend Email Marketing for WooCommerce by Omnisend <= 1.19.0

Timeline

  • 2026-06-06: other: Reported by Vimalatithyan S. Technieum
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Version 1.19.1 released to address the issue

References

Related threats