CVE-2026-57739: WordPress AcyMailing SMTP Newsletter plugin <= 10.11.0 - SQL Injection vulnerability
Published Jul 13, 2026
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0.
Affected Software
2 affected components
AcyMailing SMTP Newsletter<=10.11.0
WordPress/AcyMailing SMTP Newsletter<=10.11.0
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57739?
The severity of CVE-2026-57739 is critical with a score of 9.3.
2
How do I fix CVE-2026-57739?
To fix CVE-2026-57739, update the AcyMailing SMTP Newsletter plugin to version 10.11.1 or later.
3
What type of vulnerability is CVE-2026-57739?
CVE-2026-57739 is an SQL Injection vulnerability.
4
Who is affected by CVE-2026-57739?
The vulnerability affects users of the AcyMailing SMTP Newsletter plugin version 10.11.0 and prior.
5
What is the impact of CVE-2026-57739?
The impact of CVE-2026-57739 includes the potential for attackers to execute blind SQL injection attacks.