CVE-2026-105055: WordPress WP Mailster plugin <= 1.9.0.0 - Broken Access Control vulnerability
Published Oct 5, 2026
·Updated
Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0.
Affected Software
1 affected component
WordPress WP Mailster<=1.9.0.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wp-mailsterto a version that resolves this vulnerability.Fixed in 1.9.1.0
Event History
Oct 5, 2026
CVE Published
via MITRE·08:40 AM
Data Sourced
via MITRE·08:40 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
The issue affects WP Mailster versions through 1.9.0.0. The available data does not identify a fixed version.
2
Does exploitation require authentication or user interaction?
No. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
3
What is the expected security impact?
The reported impact is limited confidentiality impact. No integrity or availability impact is indicated by the supplied CVSS vector.