CVE-2026-15426: AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update

Published Aug 11, 2026
·
Updated

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acynotificationcms notification template, causing subsequent WordPress password-reset emails — including those targeting administrator accounts — to be silently copied to an attacker-controlled address, enabling account takeover via the captured reset link. Successful exploitation requires the site administrator to have enabled the "Send website emails with AcyMailing" option, which routes WordPress core notification emails through AcyMailing's templating system.

Affected Software

1 affected component
AcyMailing WordPress plugin<=10.11.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress to a version that resolves this vulnerability.

    Fixed in 10.11.1
  2. Configuration

    Disable the AcyMailing option "Send website emails with AcyMailing" to stop routing WordPress core notification emails through AcyMailing’s templating system.

    AcyMailing Send website emails with AcyMailing = disabled
  3. Compensating control

    Restrict access so that only trusted administrators can manage notification templates / AcyMailing settings (given the authorization bypass affects authenticated users with Subscriber+ access).

Event History

Aug 11, 2026
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15426?

The severity of CVE-2026-15426 is rated high, with a score of 8.8.

2

How do I fix CVE-2026-15426?

To fix CVE-2026-15426, upgrade the AcyMailing plugin to version 10.11.2 or later.

3

What does CVE-2026-15426 affect?

CVE-2026-15426 affects the AcyMailing WordPress plugin versions up to and including 10.11.1.

4

What type of vulnerability is CVE-2026-15426?

CVE-2026-15426 is an authorization bypass vulnerability that can lead to account takeover.

5

Who is impacted by CVE-2026-15426?

Users with Subscriber+ roles using AcyMailing versions up to 10.11.1 are impacted by CVE-2026-15426.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203