Missing Authorization in AcyMailing Plugin for WordPress
CVE-2026-5200
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 May 2026
What is CVE-2026-5200?
The AcyMailing plugin, a powerful newsletter and marketing tool for WordPress, contains a vulnerability related to Missing Authorization in versions up to and including 10.8.2. This flaw arises from inadequate verification processes, allowing authenticated attackers, who have at least subscriber-level access, to exploit the plugin’s functionalities. By leveraging this vulnerability, attackers can alter sensitive AcyMailing settings, export confidential subscriber keys, and potentially execute a chain of actions leading to the takeover of administrator accounts, especially when the targeted admin's email address is known.
Affected Version(s)
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress 0 <= 10.8.2