PT-2026-49459 · Omnisend · Omnisend Email Marketing For Woocommerce

Published

2026-06-15

·

Updated

2026-06-15

·

CVE-2026-42668

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2026-42668

Affected Products

Omnisend Email Marketing For Woocommerce