Detects WordPress installs running the AcyMailing newsletter plugin between 9.11.0 and 10.8.1 inclusive. The AcymController::call() method skips the acym_isAllowed() capability check whenever the requested task name contains the substring 'Ajax'. Any subscriber-level user can therefore invoke the configuration controller's saveAjax method through wp_ajax_acymailing_router to enable the autologin feature, create a newsletter subscriber whose cms_id points to an administrator, then visit a crafted ?autoSubId=N&subKey=KEY URL to authenticate as that administrator. Update AcyMailing to 10.8.2 or later.
Is your app exploitable through CVE-2026-3614?
Scan your domain free