{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/acymailing/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:acymailing:acymailing:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-77807"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AcyMailing (\u003c= 11.0.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","vulnerability","directory-traversal"],"_cs_type":"advisory","_cs_vendors":["AcyMailing"],"content_html":"\u003cp\u003eThe AcyMailing plugin for WordPress, a newsletter and marketing automation tool, contains a path traversal vulnerability in all versions up to and including 11.0.4. The flaw exists within the processing of the user[name] parameter. An unauthenticated remote attacker can leverage this vulnerability to perform directory traversal attacks, resulting in the unauthorized disclosure of arbitrary files stored on the underlying web server.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation is contingent upon the site administrator having the Embed images configuration option enabled within the AcyMailing settings. This vulnerability poses a significant risk to confidentiality, as it enables the retrieval of sensitive system files, configuration files, or database credentials. Defenders should monitor web server logs for requests containing path traversal sequences directed at the vulnerable component and ensure the plugin is updated to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read sensitive files on the server hosting the WordPress instance. This could lead to the exposure of configuration data, local credentials, or environment variables, potentially facilitating further unauthorized access to the web application or the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the AcyMailing WordPress plugin to a version released after 11.0.4 as soon as a patch becomes available.\u003c/li\u003e\n\u003cli\u003eDisable the Embed images feature in the AcyMailing configuration until the plugin can be updated.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to detect and block incoming HTTP requests containing directory traversal sequences like ../ directed at the plugin endpoints.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous GET or POST requests that contain high frequencies of relative path navigation characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T01:10:27Z","date_published":"2026-09-11T01:10:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-acymailing-traversal/","summary":"The AcyMailing WordPress plugin is vulnerable to unauthenticated directory traversal, allowing attackers to read arbitrary files on the server when the Embed images feature is enabled.","title":"Path Traversal Vulnerability in AcyMailing WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-acymailing-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - AcyMailing","version":"https://jsonfeed.org/version/1.1"}