CVE-2026-27327: WordPress YayMail – WooCommerce Email Customizer plugin <= 4.3.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in YayCommerce YayMail yaymail allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YayMail: from n/a through <= 4.3.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27327?
CVE-2026-27327 is categorized as a missing authorization vulnerability, which can lead to unauthorized access to sensitive functions.
How do I fix CVE-2026-27327?
To fix CVE-2026-27327, update YayMail – WooCommerce Email Customizer to the latest version that addresses this vulnerability.
Who is affected by CVE-2026-27327?
CVE-2026-27327 affects users of YayMail – WooCommerce Email Customizer versions up to and including 4.3.2.
What kind of attacks can CVE-2026-27327 enable?
CVE-2026-27327 can enable attackers to exploit incorrectly configured access controls, potentially accessing or modifying email settings.
Is there a specific version I should upgrade to for CVE-2026-27327?
Users should upgrade from any version up to 4.3.2 to the latest release of YayMail to eliminate the CVE-2026-27327 vulnerability.