What is CVE-2026-15426?
CVE-2026-15426 is an authorization bypass vulnerability in the AcyMailing plugin for WordPress, affecting all versions up to and including 10.11.1. The flaw exists because the plugin fails to properly verify user permissions for performing actions. Affected users should immediately update the plugin to the latest patched version.
Azərbaycanca: CVE-2026-15426, AcyMailing plagininin 10.11.1-ə qədər olan bütün versiyalarında aşkarlanmış avtorizasiyadan yan keçmə (authorization bypass) zəifliyidir. Bu boşluq, plaginin istifadəçi icazələrini düzgün yoxlamaması səbəbindən yaranır. Zərərçəkmiş istifadəçilər dərhal plaginini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
In which plugin was CVE-2026-15426 discovered?
CVE-2026-15426 was discovered in the AcyMailing plugin, affecting all versions up to and including 10.11.1.
What is the cause of CVE-2026-15426?
This flaw exists because the AcyMailing plugin fails to properly verify user permissions for performing actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.