Unauthenticated Remote Code Execution in AcyMailing SMTP Newsletter by Acyba
CVE-2026-94389

9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 September 2026

What is CVE-2026-94389?

A remote code execution vulnerability exists in AcyMailing SMTP Newsletter versions prior to 11.0.5. This vulnerability allows an unauthenticated attacker to execute arbitrary code on the server, potentially leading to full system compromise. Proper preventative measures must be taken to safeguard your installation, such as updating the plugin to the latest version or implementing security best practices.

Affected Version(s)

AcyMailing SMTP Newsletter <= 11.0.5

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rpgsec | Patchstack Bug Bounty Program
.