Missing Authorization Vulnerability in Mailercloud's Webform Integration
CVE-2026-39713

Currently unrated

What is CVE-2026-39713?

A missing authorization vulnerability exists in Mailercloud's integration plugin, which allows attackers to exploit incorrectly configured access control measures. This issue impacts versions of the plugin up to and including 1.0.7, potentially allowing unauthorized access to sensitive functionalities related to webforms and contact synchronization.

Affected Version(s)

Mailercloud &#8211; Integrate webforms and synchronize website contacts 0 <= 1.0.7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan | Patchstack Bug Bounty Program
.