Unauthenticated Broken Access Control in AcyChecker Anti Spam Plugin
CVE-2026-66689
6.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 August 2026
What is CVE-2026-66689?
The AcyChecker plugin for WordPress, specifically versions up to 2.0.0, is susceptible to unauthenticated broken access control. This vulnerability allows malicious actors to bypass authentication measures and gain unauthorized access to sensitive functions within the plugin. This poses a significant risk to websites utilizing the AcyChecker plugin, as it undermines the security controls designed to protect user data and uphold the integrity of the platform.
Affected Version(s)
Anti Spam and list cleaner – AcyChecker <= 2.0.0