Impact
AcyMailing for WordPress versions up to and including 11.0.4 is susceptible to a directory traversal flaw that allows an unauthenticated attacker to read arbitrary files on the server via the user[name] parameter. The vulnerability can expose sensitive configuration data or other private files, resulting in a confidentiality compromise. Exploitation requires that the plugin’s "Embed images" option be enabled, which is a prerequisite that attackers must satisfy to trigger the file read.
Affected Systems
The affected product is AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution. All releases up to version 11.0.4 are impacted, provided the "Embed images" feature is turned on in the plugin settings.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for this vulnerability. EPSS is not available, and it is not listed in CISA’s KEV catalog, suggesting that no widespread exploitation has been confirmed to date. The likely attack vector is an unauthenticated HTTP request to the plugin’s endpoint containing the user[name] parameter; the exploit does not require additional credentials or privileged access. Given the documented high CVSS score and the lack of current exploitation evidence, the threat remains significant but the probability of exploitation is uncertain without further EPSS data.
OpenCVE Enrichment