Unauthenticated Broken Access Control in AcyChecker Anti Spam Plugin
CVE-2026-66689

6.3MEDIUM

What is CVE-2026-66689?

The AcyChecker plugin for WordPress, specifically versions up to 2.0.0, is susceptible to unauthenticated broken access control. This vulnerability allows malicious actors to bypass authentication measures and gain unauthorized access to sensitive functions within the plugin. This poses a significant risk to websites utilizing the AcyChecker plugin, as it undermines the security controls designed to protect user data and uphold the integrity of the platform.

Affected Version(s)

Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vnth4nhnt | Patchstack Bug Bounty Program
.