CVE-2026-57632: WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.19.0 - Broken Access Control vulnerability
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Email Marketing for WooCommerce by Omnisend Pluginto a version that resolves this vulnerability.Fixed in 1.19.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57632?
The severity of CVE-2026-57632 is medium, with a score of 5.4.
What type of vulnerability is CVE-2026-57632?
CVE-2026-57632 is a Broken Access Control vulnerability affecting the Omnisend WordPress Email Marketing for WooCommerce plugin.
How do I fix CVE-2026-57632?
To fix CVE-2026-57632, update the WordPress Email Marketing for WooCommerce by Omnisend plugin to version 1.19.1 or higher.
What software is impacted by CVE-2026-57632?
CVE-2026-57632 affects the Omnisend WordPress Email Marketing for WooCommerce plugin version 1.19.0 and below.
What are the potential impacts of CVE-2026-57632?
The potential impact of CVE-2026-57632 includes unauthorized access to subscriber data due to broken access controls.