Executive brief
AcyMailing SMTP Newsletter, a popular WordPress plugin used for managing email marketing and newsletters, contains a critical security flaw. An attacker can use this vulnerability to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information, subscriber lists, or other private data stored on the site.
Technical details
The AcyMailing SMTP Newsletter plugin for WordPress (versions up to and including 10.11.0) is vulnerable to Blind SQL Injection due to improper neutralization of special elements in SQL commands. The vulnerability allows an unauthenticated remote attacker to execute arbitrary SQL queries against the backend database. By leveraging blind injection techniques, an attacker can exfiltrate sensitive data such as user credentials, configuration details, and subscriber information. The issue is fixed in version 10.11.1.
Affected products
- AcyMailing Newsletter Team AcyMailing SMTP Newsletter <= 10.11.0
Timeline
- 2026-04-29: disclosed: Reported by kai63001
- 2026-07-06: advisory: Patchstack advisory published
- 2026-07-13: advisory: NVD published CVE-2026-57739
- patched: Fixed in version 10.11.1