CVE-2026-3614 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 16, 2026
AcyMailing WordPress plugin - Privilege Escalation
Published: April 16, 2026Updated: April 16, 2026Remote Exploitable
Overview
AcyMailing WordPress plugin >= 9.11.0 and <= 10.8.1 contains a privilege escalation caused by missing capability check in wp_ajax_acymailing_router AJAX handler, letting authenticated subscribers access admin controllers and authenticate as other users.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated attackers can escalate privileges to admin by abusing autologin and user creation, leading to full site compromise.
Mitigation
Update to a version later than 10.8.1 or the latest available version.
References
- https://plugins.trac.wordpress.org/browser/acymailing/trunk/WpInit/Router.php#L11
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a895e2cf-9eba-4c46-b19f-d008e1058f64?source=cve
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.7.1/WpInit/Router.php#L11
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.7.1/WpInit/Router.php#L122
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.7.1/WpInit/Router.php#L230
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.7.1/back/Core/AcymController.php#L92
- https://plugins.trac.wordpress.org/browser/acymailing/tags/10.8.1/back/Core/AcymController.php#L99
Related Resources
Details
- CVE ID
- CVE-2026-3614
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_access_control
- Status
- new
CWE
- CWE-862
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H