Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend
CVE-2026-42668
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 June 2026
What is CVE-2026-42668?
A vulnerability exists in Email Marketing for WooCommerce by Omnisend, allowing unauthenticated users to exploit broken authentication mechanisms. This impacts versions up to 1.18.0, leading to unauthorized access and potential data breaches. It is crucial for users and administrators to update to the latest versions to mitigate risks associated with this flaw.
Affected Version(s)
Email Marketing for WooCommerce by Omnisend <= 1.18.0