Executive brief
AcyMailing SMTP Newsletter, a popular WordPress plugin used for managing email marketing and newsletters, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions, such as subscribers, to perform actions they should not be authorized to do. An exploit could lead to unauthorized changes to the newsletter system or cause service disruptions, potentially impacting the organization's ability to communicate with customers.
Technical details
A missing authorization vulnerability (CWE-862) exists in the AcyMailing SMTP Newsletter plugin for WordPress through version 10.11.1. The flaw stems from insufficient validation of user permissions when accessing certain functions or security levels. A remote attacker with 'Subscriber' level privileges can exploit this to execute actions typically reserved for higher-privileged users. According to the advisory, the impact includes integrity loss and high availability impact, suggesting the ability to modify configurations or disrupt newsletter services. As of the disclosure date, no official patch has been released.
Affected products
- AcyMailing Newsletter Team AcyMailing SMTP Newsletter <= 10.11.1
Timeline
- 2026-05-02: disclosed: Vulnerability reported by researcher anhcd05
- 2026-07-06: advisory: Patchstack published the vulnerability details
- 2026-07-13: advisory: CVE published in the National Vulnerability Database (NVD)