PT-2026-49459 · Omnisend+1 · Omnisend Email Marketing For Woocommerce+1

CVE-2026-42668

·

Published

2026-05-13

·

Updated

2026-06-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Email Marketing for WooCommerce by Omnisend versions prior to 1.18.1
Description An unauthenticated account takeover is possible due to the use of insufficiently random values. The generate install url() function creates an OAuth connect token based only on the Unix timestamp at page-load time using hash('sha256', time()). This method produces approximately 86,400 distinct values per day, making the token easy to predict via brute-force. An attacker can use a predicted token to authenticate to the 'POST /wp-json/omnisend-api/v1/connect' REST endpoint and replace the omnisend api key and brand id variables with their own values. This allows the redirection of customer personally identifiable information (PII) synchronization, order webhooks, and marketing communications to an unauthorized account.
Recommendations Update Email Marketing for WooCommerce by Omnisend to version 1.18.1 or later.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42668

Affected Products

Omnisend Email Marketing For Woocommerce
Omnisend-Connect