Description
Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Apply Update
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the WP Mailster plugin that permits attackers to exploit incorrectly configured access control settings. Because of the broken access control, a user lacking proper permissions can access privileged plugin functions, potentially viewing or manipulating stored email data. The weakness, identified as CWE-862, allows unauthorized users to bypass normal WordPress role checks and achieve unintended privilege escalation within the plugin scope.

Affected Systems

Affected systems include any WordPress installation running the WP Mailster plugin version 1.9.0.0 or earlier. The official product name is WP Mailster, and the vulnerability impacts all versions from the initial release up to and including 1.9.0.0.

Risk and Exploitability

The CVSS base score of 5.3 classifies the flaw as medium severity. EPSS is not available, so current exploitation potential is uncertain, yet the lack of a KEV listing implies no known large‑scale exploitation. Based on the nature of a broken access control flaw, the most likely attack vector is remote, where a logged‑in user could send crafted requests to access disallowed functions. An attacker would need to authenticate with a standard user account or exploit an existing authenticated session to benefit from the vulnerability.

Generated by OpenCVE AI on October 5, 2026 at 10:40 UTC.

Remediation

Vendor Solution

Update the WordPress WP Mailster plugin to the latest available version (at least 1.9.1.0).


OpenCVE Recommended Actions

  • Update the WP Mailster plugin to at least version 1.9.1.0 or newer.
  • Verify that access control settings for email management are correctly enforced in WordPress, ensuring that only authorized roles can view or edit mailbox data.
  • Enable audit logging for plugin actions and review logs for suspicious activity post‑upgrade.

Generated by OpenCVE AI on October 5, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0.
Title WordPress WP Mailster plugin <= 1.9.0.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T12:25:37.241Z

Reserved: 2026-10-03T00:17:03.677Z

Link: CVE-2026-105055

cve-icon Vulnrichment

Updated: 2026-10-05T12:25:03.412Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:10.583

Modified: 2026-10-05T13:16:52.077

Link: CVE-2026-105055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:45:21Z

Weaknesses