PT-2026-49459 · Omnisend+1 · Omnisend Email Marketing For Woocommerce+1
CVE-2026-42668
·
Published
2026-05-13
·
Updated
2026-06-15
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Email Marketing for WooCommerce by Omnisend versions prior to 1.18.1
Description
An unauthenticated account takeover is possible due to the use of insufficiently random values. The
generate install url() function creates an OAuth connect token based only on the Unix timestamp at page-load time using hash('sha256', time()). This method produces approximately 86,400 distinct values per day, making the token easy to predict via brute-force. An attacker can use a predicted token to authenticate to the 'POST /wp-json/omnisend-api/v1/connect' REST endpoint and replace the omnisend api key and brand id variables with their own values. This allows the redirection of customer personally identifiable information (PII) synchronization, order webhooks, and marketing communications to an unauthorized account.Recommendations
Update Email Marketing for WooCommerce by Omnisend to version 1.18.1 or later.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omnisend Email Marketing For Woocommerce
Omnisend-Connect