ZeroHour

CVE-2026-81783

large

Subscriber-Level Broken Authentication in MailMunch WordPress Plugin

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

MailMunch – Grow your Email List, a WordPress plugin used for email list building, contains a broken authentication flaw (CWE-288) in its subscriber-related functionality. The issue is reachable over the network without user interaction, and per the CVSS scoring an attacker only needs a low-privilege subscriber-level account on the affected site to trigger it. Successful exploitation bypasses the intended authentication check, allowing the attacker to alter data (low integrity impact) and potentially disrupt the site's availability (high availability impact), with no direct confidentiality loss indicated. Any WordPress site running the plugin at version 3.2.5 or earlier is affected. There is currently no evidence of exploitation: no public proof-of-concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Update the MailMunch plugin to a version newer than 3.2.5 (check the plugin's WordPress.org page for the current patched release) via the WordPress admin dashboard. If immediate patching is not possible, consider deactivating the plugin or restricting subscriber registrations on affected sites until the update is applied. Since no public PoC or in-the-wild exploitation is known, routine patch prioritization is appropriate.

Affected
MailMunch – Grow your Email List (WordPress plugin)<= 3.2.5
Estimated exposure
largeon the order of tens of thousands of sites (roughly 20,000+ active installs per WordPress.org) — The estimate is based on the plugin's publicly listed WordPress.org active-install count in the tens of thousands, though practical exploitability is narrower because the attack requires a subscriber-level account on the target site.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

Ecosystems
WordPress
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

In the news

No ingested article mentions this CVE yet.