CVE-2026-5200: AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router'
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these actions into administrator account takeover when a target administrator email address is known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5200?
CVE-2026-5200 has been classified with a high severity due to its potential for privilege escalation.
How do I fix CVE-2026-5200?
To fix CVE-2026-5200, upgrade to AcyMailing version 10.8.3 or later, which resolves the missing authorization issue.
What type of vulnerability is CVE-2026-5200?
CVE-2026-5200 is a missing authorization vulnerability that allows authenticated users to escalate their privileges.
Who is affected by CVE-2026-5200?
Users of AcyMailing plugin versions up to and including 10.8.2 are affected by CVE-2026-5200.
What is the impact of CVE-2026-5200?
The impact of CVE-2026-5200 includes unauthorized access to sensitive features by privileged users, leading to potential misuse.