{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/acyba/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AcyMailing (10.11.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Acyba"],"content_html":"\u003cp\u003eThe AcyMailing plugin for WordPress (versions 10.11.1 and earlier) contains an authorization bypass vulnerability (CVE-2026-15426) that allows authenticated users with low-level privileges (subscriber) to modify sensitive email notification templates. If the site administrator has enabled the \u0026quot;Send website emails with AcyMailing\u0026quot; feature, the plugin intercepts WordPress core notification emails and routes them through its internal templating engine.\u003c/p\u003e\n\u003cp\u003eAttackers exploit this by modifying the BCC field of the 'acy_notification_cms' template. By injecting an attacker-controlled email address into the BCC field, any password-reset request initiated by a site administrator is copied to the attacker. The attacker then intercepts the password-reset link to gain unauthorized access to the administrator account. This vulnerability poses a significant risk to WordPress sites where AcyMailing is configured to handle system-generated emails.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to a target WordPress site as a user with 'subscriber' level access or higher.\u003c/li\u003e\n\u003cli\u003eAttacker verifies that the target site has the AcyMailing \u0026quot;Send website emails with AcyMailing\u0026quot; setting enabled.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted request to the plugin's configuration endpoint to modify the 'acy_notification_cms' template.\u003c/li\u003e\n\u003cli\u003eAttacker inserts an external email address controlled by the attacker into the BCC parameter of the template.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a legitimate WordPress password-reset request targeting an administrator account (e.g., via /wp-login.php?action=lostpassword).\u003c/li\u003e\n\u003cli\u003eThe WordPress backend generates a password-reset notification, which is processed by AcyMailing.\u003c/li\u003e\n\u003cli\u003eAcyMailing appends the attacker's email to the BCC list and dispatches the notification to both the administrator and the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker receives the email containing the password-reset link and completes the account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full administrative account takeover of the affected WordPress site. This grants the attacker elevated privileges, allowing for site-wide data exfiltration, deployment of malicious scripts, or further compromise of the web server hosting environment. All versions up to 10.11.1 are affected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the AcyMailing plugin to version 10.11.2 or later to resolve CVE-2026-15426.\u003c/li\u003e\n\u003cli\u003eAudit active WordPress user accounts for suspicious \u0026quot;subscriber\u0026quot; roles that may be involved in testing or exploitation activities.\u003c/li\u003e\n\u003cli\u003eReview webserver logs for unauthorized POST requests directed at AcyMailing configuration endpoints that manage template settings.\u003c/li\u003e\n\u003cli\u003eTemporarily disable the \u0026quot;Send website emails with AcyMailing\u0026quot; feature if an immediate update is not possible.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-11T21:50:42Z","date_published":"2026-08-11T21:50:42Z","id":"https://feed.craftedsignal.io/briefs/2026-08-acymailing-auth-bypass/","summary":"An authorization bypass vulnerability in AcyMailing allows authenticated subscribers to hijack WordPress password reset emails by modifying notification template BCC fields.","title":"Authorization Bypass in AcyMailing WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-acymailing-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Acyba","version":"https://jsonfeed.org/version/1.1"}