The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these actions into administrator account takeover when a target administrator email address is known.
Metrics
Affected Vendors & Products
References
History
Wed, 20 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Acyba
Acyba acymailing – An Ultimate Newsletter Plugin And Marketing Automation Solution For Wordpress Wordpress Wordpress wordpress |
|
| Vendors & Products |
Acyba
Acyba acymailing – An Ultimate Newsletter Plugin And Marketing Automation Solution For Wordpress Wordpress Wordpress wordpress |
Wed, 20 May 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these actions into administrator account takeover when a target administrator email address is known. | |
| Title | AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router' | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-20T12:19:49.898Z
Reserved: 2026-03-31T01:30:24.976Z
Link: CVE-2026-5200
Updated: 2026-05-20T12:19:46.529Z
Status : Deferred
Published: 2026-05-20T08:16:22.860
Modified: 2026-05-20T13:54:54.890
Link: CVE-2026-5200
No data.
OpenCVE Enrichment
Updated: 2026-05-20T09:00:11Z