CVE-2026-81783
largeSubscriber-Level Broken Authentication in MailMunch WordPress Plugin
MailMunch – Grow your Email List, a WordPress plugin used for email list building, contains a broken authentication flaw (CWE-288) in its subscriber-related functionality. The issue is reachable over the network without user interaction, and per the CVSS scoring an attacker only needs a low-privilege subscriber-level account on the affected site to trigger it. Successful exploitation bypasses the intended authentication check, allowing the attacker to alter data (low integrity impact) and potentially disrupt the site's availability (high availability impact), with no direct confidentiality loss indicated. Any WordPress site running the plugin at version 3.2.5 or earlier is affected. There is currently no evidence of exploitation: no public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Update the MailMunch plugin to a version newer than 3.2.5 (check the plugin's WordPress.org page for the current patched release) via the WordPress admin dashboard. If immediate patching is not possible, consider deactivating the plugin or restricting subscriber registrations on affected sites until the update is applied. Since no public PoC or in-the-wild exploitation is known, routine patch prioritization is appropriate.
| MailMunch – Grow your Email List (WordPress plugin) | <= 3.2.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
In the news0 stories
No ingested article mentions this CVE yet.