External risk intelligence

AcyMailing SMTP Newsletter Unauthenticated Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-94389

The vulnerability affects a WordPress plugin designed for SMTP and newsletter management. Such plugins are commonly integrated into public-facing websites to handle outgoing email communications, making their functionality and associated interfaces frequently accessible via the public internet.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns an unauthenticated remote code execution vulnerability found in a popular newsletter and SMTP plugin. The issue allows an attacker to potentially compromise systems by sending specially crafted requests, bypassing authentication. The primary concern is confirming if this specific technology is in use within your environment to understand potential exposure.The AcyMailing SMTP Newsletter plugin is a tool used for managing email newsletters and sending communications from WordPress websites. This vulnerability allows unauthenticated remote code execution, meaning an attacker could potentially run malicious code on a server without needing any login credentials. The severity of such vulnerabilities lies in their potential to grant attackers full control over affected systems, leading to data breaches, malware deployment, or service disruption.

  • Unauthenticated remote code execution.
  • It can lead to full system compromise.
  • Assess relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could leverage this vulnerability by sending specially crafted network requests to a website running the affected AcyMailing SMTP Newsletter plugin. Since no authentication is required, the attacker can directly interact with the plugin's exposed features. If these features are improperly handled, it could lead to the execution of arbitrary code on the server, potentially allowing the attacker to take control of the system.

  • Unauthenticated network access needed.
  • Vulnerable plugin feature triggers execution.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary code when supported by the advisory. This may impact the confidentiality, integrity, and availability of the affected system.

  • System code execution.
  • Remote network access.
  • Compromise of system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

In real-world scenarios, teams responsible for public-facing websites, particularly those utilizing WordPress with email marketing functionalities, should lead the response. This typically involves application owners, platform engineers, and security operations teams. The initial practical step is to identify all instances of the affected technology, confirm their reachability and business criticality, and then assign an accountable owner for remediation planning.

  • Application owners should own the issue.
  • Verify public exposure and business criticality first.
  • Plan remediation, considering vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the AcyMailing SMTP Newsletter plugin?

AcyMailing SMTP Newsletter is a WordPress plugin designed to manage email marketing campaigns and handle outgoing mail server communications directly from a website's dashboard.

What does CVE-2026-94389 mean for system security?

This vulnerability is classified as CWE-94, or Improper Control of Generation of Code. It means the software fails to sanitize inputs properly, allowing an attacker to inject and execute their own commands on your server.

How does an attacker trigger this RCE vulnerability?

An attacker triggers this by sending specially crafted network requests to the plugin. Since the flaw is unauthenticated, they do not need valid login credentials. Simply visiting the site or interacting with standard plugin features that do not use the vulnerable code path will not trigger the issue.

Is my website at risk from this vulnerability?

According to Halo Surface Signal, this plugin is typically used on public-facing websites to manage email communications. Because the plugin's features are often exposed to the internet, any instance running the affected versions is likely accessible to remote attackers.

What is the first step to address CVE-2026-94389?

The immediate priority is to conduct an inventory to identify all WordPress sites in your environment running this plugin. Once located, confirm if the version is 11.0.5 or older, assess the site's public accessibility, and designate an owner to coordinate the necessary security updates.

References