CVE-2026-15426 (GCVE-0-2026-15426)
Vulnerability from cvelistv5
Published
2026-08-11 18:26
Modified
2026-08-12 16:58
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-269 - Improper Privilege Management
Summary
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acy_notification_cms notification template, causing subsequent WordPress password-reset emails — including those targeting administrator accounts — to be silently copied to an attacker-controlled address, enabling account takeover via the captured reset link. Successful exploitation requires the site administrator to have enabled the "Send website emails with AcyMailing" option, which routes WordPress core notification emails through AcyMailing's templating system.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| acyba | AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress |
Version: 0 ≤ 10.11.1 |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15426",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-12T16:05:40.310260Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-12T16:58:26.640Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "AcyMailing \u2013 An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress",
"vendor": "acyba",
"versions": [
{
"lessThanOrEqual": "10.11.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "d.v4n_s3c"
}
],
"descriptions": [
{
"lang": "en",
"value": "The AcyMailing \u2013 An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acy_notification_cms notification template, causing subsequent WordPress password-reset emails \u2014 including those targeting administrator accounts \u2014 to be silently copied to an attacker-controlled address, enabling account takeover via the captured reset link. Successful exploitation requires the site administrator to have enabled the \"Send website emails with AcyMailing\" option, which routes WordPress core notification emails through AcyMailing\u0027s templating system."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-11T18:26:32.125Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0c187d78-9f1d-4e55-a611-755ee30f855b?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Controllers/Mails/Edition.php#L344"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Controllers/Dashboard/Walkthrough.php#L222"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Core/AcymController.php#L99"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/WpInit/Router.php#L122"
},
{
"url": "https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Classes/MailClass.php#L1496"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3632690/acymailing"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-07-10T16:47:29.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-08-11T06:12:22.000Z",
"value": "Disclosed"
}
],
"title": "AcyMailing \u003c= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-15426",
"datePublished": "2026-08-11T18:26:32.125Z",
"dateReserved": "2026-07-10T16:32:12.807Z",
"dateUpdated": "2026-08-12T16:58:26.640Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"vulnerability-lookup:meta": {
"vulnrichment": {
"containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-15426\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-08-12T16:05:40.310260Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-08-12T16:07:08.740Z\"}}], \"cna\": {\"title\": \"AcyMailing \u003c= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update\", \"credits\": [{\"lang\": \"en\", \"type\": \"finder\", \"value\": \"d.v4n_s3c\"}], \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 8.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}}], \"affected\": [{\"vendor\": \"acyba\", \"product\": \"AcyMailing \\u2013 An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"10.11.1\"}], \"defaultStatus\": \"unaffected\"}], \"timeline\": [{\"lang\": \"en\", \"time\": \"2026-07-10T16:47:29.000Z\", \"value\": \"Vendor Notified\"}, {\"lang\": \"en\", \"time\": \"2026-08-11T06:12:22.000Z\", \"value\": \"Disclosed\"}], \"references\": [{\"url\": \"https://www.wordfence.com/threat-intel/vulnerabilities/id/0c187d78-9f1d-4e55-a611-755ee30f855b?source=cve\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Controllers/Mails/Edition.php#L344\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Controllers/Dashboard/Walkthrough.php#L222\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Core/AcymController.php#L99\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/WpInit/Router.php#L122\"}, {\"url\": \"https://plugins.trac.wordpress.org/browser/acymailing/tags/10.10.2/back/Classes/MailClass.php#L1496\"}, {\"url\": \"https://plugins.trac.wordpress.org/changeset/3632690/acymailing\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"The AcyMailing \\u2013 An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acy_notification_cms notification template, causing subsequent WordPress password-reset emails \\u2014 including those targeting administrator accounts \\u2014 to be silently copied to an attacker-controlled address, enabling account takeover via the captured reset link. Successful exploitation requires the site administrator to have enabled the \\\"Send website emails with AcyMailing\\\" option, which routes WordPress core notification emails through AcyMailing\u0027s templating system.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-269\", \"description\": \"CWE-269 Improper Privilege Management\"}]}], \"providerMetadata\": {\"orgId\": \"b15e7b5b-3da4-40ae-a43c-f7aa60e62599\", \"shortName\": \"Wordfence\", \"dateUpdated\": \"2026-08-11T18:26:32.125Z\"}}}",
"cveMetadata": "{\"cveId\": \"CVE-2026-15426\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-12T16:58:26.640Z\", \"dateReserved\": \"2026-07-10T16:32:12.807Z\", \"assignerOrgId\": \"b15e7b5b-3da4-40ae-a43c-f7aa60e62599\", \"datePublished\": \"2026-08-11T18:26:32.125Z\", \"assignerShortName\": \"Wordfence\"}",
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
}
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…