SQL Injection Vulnerability in AcyMailing SMTP Plugin by AcyMailing Newsletter Team
CVE-2026-57739

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57739?

A vulnerability in the AcyMailing SMTP Newsletter plugin allows for Blind SQL Injection, enabling an attacker to manipulate and execute unauthorized SQL commands. This can compromise sensitive data and affect the integrity of the database. Sites running versions up to and including 10.11.0 are particularly at risk and should seek immediate updates to mitigate potential exploitation.

Affected Version(s)

AcyMailing SMTP Newsletter 0 <= 10.11.0

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kai63001 | Patchstack Bug Bounty Program
.