Description
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-07-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AcyMailing plugin for WordPress is vulnerable to a stored cross‑site scripting flaw that is triggered by the ‘alignment’ attribute. The problem occurs because and output content is not correctly escaped, allowing an authenticated user with contributor‑level or higher privileges to inject arbitrary scripts into newsletters or email templates. When another user views a page that contains the injected content, the malicious script executes in that user’s browser, potentially leading to session hijacking, defacement, or execution of additional payloads.

Affected Systems

All WordPress installations that have the AcyMailing plugin from acyba with a version of 10.10.2 or earlier installed are affected. The risk applies to any user who has the ability to modify newsletter or email content, which includes contributor‑level accounts and above.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity risk, while the EPSS score of less than 1% suggests the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated contributor‑or‑higher user; the attacker must submit crafted content containing the malicious script through the plugin’s content editor, after which the code is stored and will run when the page is viewed by any user. No additional network or system prerequisites are stated in the CVE data.

Generated by OpenCVE AI on July 29, 2026 at 12:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the AcyMailing plugin to the latest release that contains the fix for the stored cross‑site scripting issue.
  • I If an upgrade cannot be performed immediately, limit contributor‑level users from editing newsletter or email content, or disable the use of the alignment attribute for content created by them.
  • After applying the patch or implementing the restriction, review existing stored content for injected scripts, and sanitize or re‑save affected entries to remove malicious code.

Generated by OpenCVE AI on July 29, 2026 at 12:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Acyba
Acyba acymailing – An Ultimate Newsletter Plugin And Marketing Automation Solution For Wordpress
Wordpress
Wordpress wordpress
Vendors & Products Acyba
Acyba acymailing – An Ultimate Newsletter Plugin And Marketing Automation Solution For Wordpress
Wordpress
Wordpress wordpress

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Acyba Acymailing – An Ultimate Newsletter Plugin And Marketing Automation Solution For Wordpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-09T14:32:39.494Z

Reserved: 2026-06-12T20:24:56.022Z

Link: CVE-2026-12170

cve-icon Vulnrichment

Updated: 2026-07-09T14:32:36.422Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')