PatchSiren cyber security CVE debrief
CVE-2026-5200 acyba CVE debrief
The AcyMailing plugin for WordPress has a Missing Authorization vulnerability in versions up to 10.8.2. This allows authenticated attackers with subscriber-level access to modify AcyMailing configuration, export subscriber secret keys, and potentially take over administrator accounts. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Affected WordPress users should prioritize updating the plugin and restricting access to AcyMailing configuration.
- Vendor
- acyba
- Product
- AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-07-24
Who should care
WordPress users with the AcyMailing plugin installed, particularly those with subscriber-level access or higher, should be aware of this vulnerability and take immediate action to protect their sites. Affected operators should review their AcyMailing configuration and ensure that only authorized personnel have access to sensitive settings.
Technical summary
The AcyMailing plugin for WordPress is vulnerable to Missing Authorization due to improper verification of user authorization. This allows authenticated attackers with subscriber-level access and above to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these actions into administrator account takeover when a target administrator email address is known. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.
Defensive priority
High priority due to potential for administrator account takeover and sensitive configuration modification
Recommended defensive actions
- Update AcyMailing plugin to a version beyond 10.8.2
- Restrict access to AcyMailing configuration for users with subscriber-level access
- Monitor for suspicious activity related to AcyMailing configuration changes and subscriber key exports
- Implement additional security measures such as two-factor authentication for administrator accounts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-05-20T08:16:22.860Z and last modified on 2026-07-24T10:10:00.197Z. The NVD entry is currently Deferred. The vulnerability was reported by [email protected]. Evidence of exploitation has not been confirmed, but defenders should verify affected AcyMailing plugin deployments and review configuration for potential unauthorized changes.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-20T08:16:22.860Z and has not been modified since then. The NVD entry is currently Deferred.