CVE-2026-15426: AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the BCC field of the acynotificationcms notification template, causing subsequent WordPress password-reset emails — including those targeting administrator accounts — to be silently copied to an attacker-controlled address, enabling account takeover via the captured reset link. Successful exploitation requires the site administrator to have enabled the "Send website emails with AcyMailing" option, which routes WordPress core notification emails through AcyMailing's templating system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressto a version that resolves this vulnerability.Fixed in 10.11.1 - Configuration
Disable the AcyMailing option "Send website emails with AcyMailing" to stop routing WordPress core notification emails through AcyMailing’s templating system.
AcyMailing Send website emails with AcyMailing = disabled - Compensating control
Restrict access so that only trusted administrators can manage notification templates / AcyMailing settings (given the authorization bypass affects authenticated users with Subscriber+ access).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15426?
The severity of CVE-2026-15426 is rated high, with a score of 8.8.
How do I fix CVE-2026-15426?
To fix CVE-2026-15426, upgrade the AcyMailing plugin to version 10.11.2 or later.
What does CVE-2026-15426 affect?
CVE-2026-15426 affects the AcyMailing WordPress plugin versions up to and including 10.11.1.
What type of vulnerability is CVE-2026-15426?
CVE-2026-15426 is an authorization bypass vulnerability that can lead to account takeover.
Who is impacted by CVE-2026-15426?
Users with Subscriber+ roles using AcyMailing versions up to 10.11.1 are impacted by CVE-2026-15426.