PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5200 acyba CVE debrief

The AcyMailing plugin for WordPress has a Missing Authorization vulnerability in versions up to 10.8.2. This allows authenticated attackers with subscriber-level access to modify AcyMailing configuration, export subscriber secret keys, and potentially take over administrator accounts. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Affected WordPress users should prioritize updating the plugin and restricting access to AcyMailing configuration.

Vendor
acyba
Product
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-20
Original CVE updated
2026-07-24
Advisory published
2026-05-20
Advisory updated
2026-07-24

Who should care

WordPress users with the AcyMailing plugin installed, particularly those with subscriber-level access or higher, should be aware of this vulnerability and take immediate action to protect their sites. Affected operators should review their AcyMailing configuration and ensure that only authorized personnel have access to sensitive settings.

Technical summary

The AcyMailing plugin for WordPress is vulnerable to Missing Authorization due to improper verification of user authorization. This allows authenticated attackers with subscriber-level access and above to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these actions into administrator account takeover when a target administrator email address is known. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.

Defensive priority

High priority due to potential for administrator account takeover and sensitive configuration modification

Recommended defensive actions

  • Update AcyMailing plugin to a version beyond 10.8.2
  • Restrict access to AcyMailing configuration for users with subscriber-level access
  • Monitor for suspicious activity related to AcyMailing configuration changes and subscriber key exports
  • Implement additional security measures such as two-factor authentication for administrator accounts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-05-20T08:16:22.860Z and last modified on 2026-07-24T10:10:00.197Z. The NVD entry is currently Deferred. The vulnerability was reported by [email protected]. Evidence of exploitation has not been confirmed, but defenders should verify affected AcyMailing plugin deployments and review configuration for potential unauthorized changes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-5200 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-5200

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-5200 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5200

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.