Impact
The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to a broken access control flaw that permits unauthorized manipulation of subscriber information. The flaw is categorized as CWE‑862 and undermines the confidentiality and integrity of the subscriber database. Based on the description, it is inferred that an attacker could potentially access or modify subscriber data beyond the intended user permissions.
Affected Systems
WordPress sites installed with the AcyMailing SMTP Newsletter plugin version 10.11.1 or earlier are affected. The plugin should be upgraded to at least version 11.0.0 to remove the defect.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no current evidence of public exploitation. Based on the description, the likely attack vector involves either authenticated access to the WordPress site with subscriber‑management privileges or discovery of exposed plugin endpoints that lack proper authorization checks. Successful exploitation could allow an attacker to alter subscriber lists, potentially enabling spam campaigns or unauthorized data collection.
OpenCVE Enrichment