Description
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Published: 2026-08-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to a broken access control flaw that permits unauthorized manipulation of subscriber information. The flaw is categorized as CWE‑862 and undermines the confidentiality and integrity of the subscriber database. Based on the description, it is inferred that an attacker could potentially access or modify subscriber data beyond the intended user permissions.

Affected Systems

WordPress sites installed with the AcyMailing SMTP Newsletter plugin version 10.11.1 or earlier are affected. The plugin should be upgraded to at least version 11.0.0 to remove the defect.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no current evidence of public exploitation. Based on the description, the likely attack vector involves either authenticated access to the WordPress site with subscriber‑management privileges or discovery of exposed plugin endpoints that lack proper authorization checks. Successful exploitation could allow an attacker to alter subscriber lists, potentially enabling spam campaigns or unauthorized data collection.

Generated by OpenCVE AI on August 13, 2026 at 18:13 UTC.

Remediation

Vendor Solution

Update the WordPress AcyMailing SMTP Newsletter plugin to the latest available version (at least 11.0.0).


OpenCVE Recommended Actions

  • Upgrade the AcyMailing SMTP Newsletter plugin to version 11.0.0 or newer.
  • Restrict subscriber‑management capabilities to trusted administrator accounts and enforce strong authentication, including two‑factor authentication.
  • Audit the plugin’s REST and AJAX endpoints to confirm that each requires appropriate role‑based access control and remove or secure any that are exposed without authorization.

Generated by OpenCVE AI on August 13, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Acymailing Newsletter Team
Acymailing Newsletter Team acymailing Smtp Newsletter
Wordpress
Wordpress wordpress
Vendors & Products Acymailing Newsletter Team
Acymailing Newsletter Team acymailing Smtp Newsletter
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
Title WordPress AcyMailing SMTP Newsletter plugin <= 10.11.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Acymailing Newsletter Team Acymailing Smtp Newsletter
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:48:20.320Z

Reserved: 2026-02-25T12:14:40.739Z

Link: CVE-2026-28181

cve-icon Vulnrichment

Updated: 2026-08-13T14:25:09.951Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:59.800

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T18:15:04Z

Weaknesses