Executive brief
MailMunch is a popular WordPress plugin used to grow email subscriber lists and manage email marketing campaigns. The plugin contains a broken authentication vulnerability that allows attackers to bypass login checks or impersonate other users without requiring a password, potentially giving them access to subscriber data and email marketing campaigns.
Technical details
The vulnerability is a broken authentication issue in MailMunch – Grow your Email List plugin versions 3.2.5 and earlier. It allows attackers with subscriber-level privileges to bypass authentication mechanisms or authenticate as other users without valid credentials. The attack requires subscriber-level access to the WordPress site. This vulnerability could lead to unauthorized access to email lists, subscriber data, and campaign management features. No official patch was available as of the advisory publication date.
Affected products
- MailMunch Grow your Email List <= 3.2.5
Timeline
- 2026-09-10: disclosed: CVE-2026-81783 published
- 2026-04-28: other: Vulnerability reported to Patchstack by Jakub Herman