Impact
The AcyMailing plugin for WordPress is vulnerable to a stored cross‑site scripting flaw that is triggered by the ‘alignment’ attribute. The problem occurs because and output content is not correctly escaped, allowing an authenticated user with contributor‑level or higher privileges to inject arbitrary scripts into newsletters or email templates. When another user views a page that contains the injected content, the malicious script executes in that user’s browser, potentially leading to session hijacking, defacement, or execution of additional payloads.
Affected Systems
All WordPress installations that have the AcyMailing plugin from acyba with a version of 10.10.2 or earlier installed are affected. The risk applies to any user who has the ability to modify newsletter or email content, which includes contributor‑level accounts and above.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity risk, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated contributor‑or‑higher user; the attacker must submit crafted content containing the malicious script through the plugin’s content editor, after which the code is stored and will run when the page is viewed by any user. No additional network or system prerequisites are stated in the CVE data.
OpenCVE Enrichment