Impact
AcyMailing’s SMTP Newsletter plugin contains a missing authorization flaw that allows any user who can reach its web endpoints to invoke privileged actions without proper authentication checks. This broken access control, identified as CWE‑862, can be leveraged to modify newsletter settings, view or delete subscriber records, or otherwise alter configuration that should be restricted to administrators.
Affected Systems
The vulnerability affects all releases of the AcyMailing SMTP Newsletter plugin from the initial version through 10.11.1 inclusive. Any WordPress site that has installed the plugin within this version range is potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 marks the issue as moderate to high severity, and the EPSS score of less than 1 % indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The most plausible attack vector is a remote web request to one of the plugin’s endpoints; an attacker who can reach those URLs can exploit the missing authorization check without needing valid credentials.
OpenCVE Enrichment