Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical0
High2
Medium1
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2026-07-09

CVE-2026-12170 - And Marketing Automation Solution For Wordpress Plugin

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN And Marketing Automation Solution For Wordpress

CVE-2026-12170

MEDIUM CVSS 6.4 2026-07-09
Threat Entry Updated 2026-06-17

CVE-2026-5200 - And Marketing Automation Solution For Wordpress Plugin

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify privileged AcyMailing configuration, export subscriber secret keys, and chain these actions into administrator account takeover when a target administrator email address is known.

PLUGIN And Marketing Automation Solution For Wordpress

CVE-2026-5200

HIGH CVSS 8.8 2026-05-20
Threat Entry Updated 2024-09-27

CVE-2024-7384 - And Marketing Automation Solution For Wordpress Plugin

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the acym_extractArchive function in all versions up to, and including, 9.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

PLUGIN And Marketing Automation Solution For Wordpress

CVE-2024-7384

HIGH CVSS 7.5 2024-08-22
Scroll to top