Description
Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Published: 2026-09-30
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Unauthenticated Remote Code Execution within the AcyMailing SMTP Newsletter plugin allows an attacker to inject and execute arbitrary PHP code. This flaw, identified as CWE-94, enables full compromise of the affected WordPress site, compromising confidentiality, integrity, and availability of the entire web application.

Affected Systems

The vulnerability affects the WordPress AcyMailing SMTP Newsletter plugin from the AcyMailing Newsletter Team, specifically all releases up to and including version 11.0.5. Users running these versions are at risk of exploitation if the plugin is loaded on a publicly accessible WordPress instance.

Risk and Exploitability

The flaw carries a CVSS score of 9, indicating critical severity. EPSS data is not available, so the current estimation of exploitation probability cannot be quantified, but the lack of authentication requirements means any user capable of loading the plugin could exploit it. It is not listed in CISA's KEV catalog, yet the inherent risk warrants immediate attention.

Generated by OpenCVE AI on September 30, 2026 at 15:46 UTC.

Remediation

Vendor Solution

Update the WordPress AcyMailing SMTP Newsletter plugin to the latest available version (at least 11.1.0).


OpenCVE Recommended Actions

  • Apply the vendor‑provided patch by upgrading the AcyMailing SMTP Newsletter plugin to version 11.1.0 or higher.
  • Disable or deactivate the plugin until the update is completed to eliminate the attack surface.
  • Configure the server’s file permissions and web‑server configuration to prevent unauthorized execution of PHP code in the plugin’s directory.

Generated by OpenCVE AI on September 30, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote Code Execution (RCE) in AcyMailing SMTP Newsletter <= 11.0.5 versions.
Title WordPress AcyMailing SMTP Newsletter plugin <= 11.0.5 - Remote Code Execution (RCE) vulnerability
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:17:03.665Z

Reserved: 2026-09-21T13:10:57.909Z

Link: CVE-2026-94389

cve-icon Vulnrichment

Updated: 2026-09-30T13:16:25.599Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:26.840

Modified: 2026-09-30T14:17:49.070

Link: CVE-2026-94389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:00:15Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')