Impact
AcyMailing’s SMTP Newsletter plugin contains a missing authorization flaw that allows any actor who can reach its web endpoints to invoke privileged actions without proper authentication checks. The vulnerability, classified as CWE‑862, would let an attacker modify newsletter settings, view or delete subscriber records, or otherwise alter configuration that should be restricted to site administrators.
Affected Systems
The flaw affects all releases of the AcyMailing SMTP Newsletter plugin from the initial version through 10.11.1 inclusive. Any WordPress site that has installed the plugin within this version range is potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 marks the issue as moderate to high severity, and the EPSS score of less than 1 % indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. The likely attack vector is a remote web request to one of the plugin’s administrative URLs; it is inferred that any user who can reach those URLs can exploit the missing authorization check without needing valid credentials.
OpenCVE Enrichment