All verified exploits

CVE-2026-3614 Subscriber-to-Admin Privilege Escalation via AcyMailing AJAX Router

Deterministic high WordPress Added cve-verified-cve-2026-3614

Detects WordPress installs running the AcyMailing newsletter plugin between 9.11.0 and 10.8.1 inclusive. The AcymController::call() method skips the acym_isAllowed() capability check whenever the requested task name contains the substring 'Ajax'. Any subscriber-level user can therefore invoke the configuration controller's saveAjax method through wp_ajax_acymailing_router to enable the autologin feature, create a newsletter subscriber whose cms_id points to an administrator, then visit a crafted ?autoSubId=N&subKey=KEY URL to authenticate as that administrator. Update AcyMailing to 10.8.2 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-3614?

Scan your domain free