Executive brief
AcyMailing is an email marketing platform used in Joomla and WordPress to manage newsletters and campaigns. The Enterprise extension before version 11.1.0 allows unauthenticated attackers to delete arbitrary files on the server—including critical configuration files—by exploiting how the system handles file-type custom fields, potentially causing complete system compromise or data loss.
Technical details
The vulnerability exists in AcyMailing Enterprise's handling of file-type custom fields, where a subscriber can store a file path and trigger deletion of that file when the field is cleared. The vulnerability permits path traversal, allowing deletion of files outside the intended upload directory. No authentication is required, and the attack is triggered through normal field-clearing operations.
Affected products
- AcyMailing AcyMailing Enterprise < 11.1.0
Timeline
- 2026-09-26: disclosed