Impact
AcyMailing for WordPress has an authorization bypass that lets an authenticated user with subscriber level or higher overwrite the BCC field of the acy_notification_cms notification template. The altered BCC causes all WordPress password‑reset emails, including those sent to administrators, to be silently copied to the attacker’s address. Capturing the reset link gives the attacker control over the target account. The flaw is a classic failed authorization issue (CWE‑269).
Affected Systems
WordPress sites that have installed AcyMailing version 10.11.1 or older and have enabled the "Send website emails with AcyMailing" option are vulnerable. No specific operating system or WordPress core version is required beyond the plugin’s compatibility, but the email‑routing option must be active for the flaw to be exploitable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is below 1%, implying a low probability of widespread exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is internal: the attacker must be logged in with a subscriber‑level account that has already been authenticated. Successful exploitation also requires that the site administrator has the email‑routing option enabled; disabling it prevents this attack.
OpenCVE Enrichment