PT-2026-33267 · WordPress · Acymailing
Ren Voza
·
Published
2026-04-16
·
Updated
2026-04-20
·
CVE-2026-3614
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AcyMailing versions 9.11.0 through 10.8.1
Description
A missing capability check on the 'wp ajax acymailing router' AJAX handler allows authenticated attackers with Subscriber-level access or higher to access admin-only controllers, including configuration management. This flaw enables the activation of the autologin feature and the creation of a malicious newsletter subscriber with an injected
cms id pointing to any user, allowing the attacker to authenticate as that user, including administrators.Recommendations
Update to version 10.8.2.
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acymailing