Unauthenticated Arbitrary File Deletion Vulnerability in AcyMailing SMTP Newsletter by Acyba
CVE-2026-95588

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 October 2026

What is CVE-2026-95588?

The AcyMailing SMTP Newsletter plugin contains a vulnerability that allows unauthenticated users to delete arbitrary files. This issue affects versions 11.0.5 and earlier, posing a significant risk as it can be exploited without user authentication. Taking immediate action to update to the latest patched version is critical for maintaining the security of your system.

Affected Version(s)

AcyMailing SMTP Newsletter <= 11.0.5

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oly Hossen | Patchstack Bug Bounty Program
.