Impact
Unauthenticated Remote Code Execution within the AcyMailing SMTP Newsletter plugin allows an attacker to inject and execute arbitrary PHP code. This flaw, identified as CWE-94, enables full compromise of the affected WordPress site, compromising confidentiality, integrity, and availability of the entire web application.
Affected Systems
The vulnerability affects the WordPress AcyMailing SMTP Newsletter plugin from the AcyMailing Newsletter Team, specifically all releases up to and including version 11.0.5. Users running these versions are at risk of exploitation if the plugin is loaded on a publicly accessible WordPress instance.
Risk and Exploitability
The flaw carries a CVSS score of 9, indicating critical severity. EPSS data is not available, so the current estimation of exploitation probability cannot be quantified, but the lack of authentication requirements means any user capable of loading the plugin could exploit it. It is not listed in CISA's KEV catalog, yet the inherent risk warrants immediate attention.
OpenCVE Enrichment