Plugin Vulnerability Hub
Plugin 6 known issues Latest disclosed May 19, 2026

AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Vulnerabilities

Review known vulnerability records for the WordPress plugin AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress (`acymailing`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-5200, CVE-2026-3614 and CVE-2025-24617, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
6
High or Critical
3
Patch Coverage
100%
Last Updated
May 19, 2026
Related Security Guides

Use these guides while reviewing AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
6
1. Match the Package
Confirm the installed WordPress plugin slug is acymailing before acting on any CVE from this cluster.
2. Sort by Severity
Start with 3 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
6 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
6
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2026-5200
AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privileg...
Privilege Escalation Versions up to 10.8.2 10.9.0 CVSS 8.8
CVE-2026-3614
AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Pr...
Privilege Escalation 9.11.0 through 10.8.1 10.8.2 CVSS 8.8
CVE-2024-7384
AcyMailing <= 9.7.2 - Authenticated (Subscriber+) Arbitrary File Upload via acym_ext...
Remote Code Execution Versions up to 9.7.2 9.8.0 CVSS 7.5
CVE-2025-24617
AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for Wor...
Cross-Site Scripting Versions up to 9.11.0 9.11.1 CVSS 6.1
CVE-2023-41867
AcyMailing SMTP Newsletter <= 8.6.2 - Reflected Cross-Site Scripting
Cross-Site Scripting Versions up to 8.6.2 8.6.3 CVSS 6.1
CVE-2021-24288
AcyMailing SMTP Newsletter < 7.5.0 - Open Redirect
Vulnerability Versions before 7.5.0 7.5.0 CVSS 6.1
CVE-2026-5200 High 10.9.0
CVE-2026-5200 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Privilege Escalation

AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router'

CVE-2026-3614 High 10.8.2
CVE-2026-3614 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Privilege Escalation

AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

CVE-2024-7384 High 9.8.0
CVE-2024-7384 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Remote Code Execution

AcyMailing <= 9.7.2 - Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive Function

CVE-2025-24617 Medium 9.11.1
CVE-2025-24617 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Cross-Site Scripting

AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 9.11.0 - Reflected Cross-Site Scripting

CVE-2023-41867 Medium 8.6.3
CVE-2023-41867 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Cross-Site Scripting

AcyMailing SMTP Newsletter <= 8.6.2 - Reflected Cross-Site Scripting

CVE-2021-24288 Medium 7.5.0
CVE-2021-24288 AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress Vulnerability

AcyMailing SMTP Newsletter < 7.5.0 - Open Redirect

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
6 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 3 high severity findings.
Recent CVEs
CVE-2026-5200, CVE-2026-3614 and CVE-2025-24617
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-5200
CVE-2026-5200: AcyMailing <= 10.8.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via 'acymailing_router'

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perfo...

Published
May 19, 2026
Patched Release
10.9.0
Affected Versions
Versions up to 10.8.2
Next Step
Update to 10.9.0 or newer if supported.
Plugin High Patched: Yes CVE-2026-3614
CVE-2026-3614: AcyMailing 9.11.0 - 10.8.1 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing capability check on the `wp_ajax_acymailing_router` AJAX handler. This makes it possible for authenticated attackers, with Subscribe...

Published
Apr 15, 2026
Patched Release
10.8.2
Affected Versions
9.11.0 through 10.8.1
Next Step
Update to 10.8.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-24617
CVE-2025-24617: AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 9.11.0 - Reflected Cross-Site Scripting

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 9.11.0 due to insufficient input sanitization and output escaping. This makes...

Published
Dec 30, 2024
Patched Release
9.11.1
Affected Versions
Versions up to 9.11.0
Next Step
Update to 9.11.1 or newer if supported.
Plugin High Patched: Yes CVE-2024-7384
CVE-2024-7384: AcyMailing <= 9.7.2 - Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive Function

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the acym_extractArchive function in all versions up to, and including, 9.7.2. This ma...

Published
Aug 21, 2024
Patched Release
9.8.0
Affected Versions
Versions up to 9.7.2
Next Step
Update to 9.8.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-41867
CVE-2023-41867: AcyMailing SMTP Newsletter <= 8.6.2 - Reflected Cross-Site Scripting

The AcyMailing SMTP Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

Published
Sep 05, 2023
Patched Release
8.6.3
Affected Versions
Versions up to 8.6.2
Next Step
Update to 8.6.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24288
CVE-2021-24288: AcyMailing SMTP Newsletter < 7.5.0 - Open Redirect

When subscribing using AcyMailing versions before 7.5.0, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

Published
Apr 29, 2021
Patched Release
7.5.0
Affected Versions
Versions before 7.5.0
Next Step
Update to 7.5.0 or newer if supported.