Junglewise Threat Intelligence

CVE-2026-65448: AcyMailing AcyChecker unauthenticated XSS

CVE-2026-65448 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Vendors: AcyMailing Newsletter Team.

Executive brief

AcyChecker, a WordPress plugin used for email list cleaning and anti-spam protection, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack sessions, redirect users to malicious websites, or deface the site. This vulnerability affects all versions up to and including 1.8.1.

Technical details

AcyChecker (Anti Spam and list cleaner) versions 1.8.1 and below are vulnerable to Unauthenticated Reflected Cross-Site Scripting (XSS). The vulnerability exists due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated attacker can exploit this by tricking a user into performing an action, such as clicking a malicious link, which executes arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking or unauthorized actions performed on behalf of the user. The issue is resolved in version 2.0.0.

Affected products

  • AcyMailing Newsletter Team Anti Spam and list cleaner – AcyChecker <= 1.8.1

Timeline

  • 2026-07-17: disclosed: Reported by Trương Hữu Phúc
  • 2026-07-27: advisory: Published by Patchstack and NVD
  • 2026-07-27: patched: Version 2.0.0 released to address the vulnerability

References