PatchSiren

acyba CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH acyba CVE published 2026-05-20

CVE-2026-5200

The AcyMailing plugin for WordPress has a Missing Authorization vulnerability in versions up to 10.8.2. This allows authenticated attackers with subscriber-level access to modify AcyMailing configuration, export subscriber secret keys, and potentially take over administrator accounts. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Affected WordPress users should prioritize u [truncated]