Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 18 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Yaycommerce Yaycommerce yaymail – Woocommerce Email Customizer |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Yaycommerce Yaycommerce yaymail – Woocommerce Email Customizer |
Wed, 18 Feb 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and activation due to missing capability checks on the 'yaymail_install_yaysmtp' AJAX action and `/yaymail/v1/addons/activate` REST endpoint in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to install and activate the YaySMTP plugin. | |
| Title | YayMail <= 4.3.2 - Missing Authorization to Authenticated (Shop Manager+) Plugin Installation and Activation | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-18T12:52:05.436Z
Reserved: 2026-02-03T14:41:20.453Z
Link: CVE-2026-1831
Updated: 2026-02-18T12:25:02.669Z
Status : Awaiting Analysis
Published: 2026-02-18T08:16:14.873
Modified: 2026-02-18T17:51:53.510
Link: CVE-2026-1831
No data.
OpenCVE Enrichment
Updated: 2026-02-18T10:32:27Z