PT-2026-70835 · WordPress · Acymailing

·

CVE-2026-15426

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress versions prior to 10.11.2
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with subscriber-level access or higher can overwrite the BCC field of the acy notification cms notification template. This allows subsequent WordPress password-reset emails, including those for administrator accounts, to be silently copied to an address controlled by the attacker, potentially leading to account takeover via the captured reset link. This issue is exploitable only if the site administrator has enabled the "Send website emails with AcyMailing" option, which routes core WordPress notification emails through the AcyMailing templating system.
Recommendations Update to a version newer than 10.11.1. Disable the "Send website emails with AcyMailing" option to prevent the routing of core notification emails through the vulnerable templating system.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15426

Affected Products

Acymailing