PT-2026-70835 · WordPress · Acymailing
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress versions prior to 10.11.2
Description
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with subscriber-level access or higher can overwrite the BCC field of the
acy notification cms notification template. This allows subsequent WordPress password-reset emails, including those for administrator accounts, to be silently copied to an address controlled by the attacker, potentially leading to account takeover via the captured reset link. This issue is exploitable only if the site administrator has enabled the "Send website emails with AcyMailing" option, which routes core WordPress notification emails through the AcyMailing templating system.Recommendations
Update to a version newer than 10.11.1.
Disable the "Send website emails with AcyMailing" option to prevent the routing of core notification emails through the vulnerable templating system.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acymailing