Sceawere

Vulnerability Detail

CVE-2026-105055UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Mailster Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
10h ago
Vendor
WP Mailster
Product
WP Mailster
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T09:17:10.583Z",
  "pubdate": "2026-10-05T09:17:10.583Z",
  "executiveSummary": "A missing authorization vulnerability exists in the WP Mailster plugin, identified within the product's access control mechanisms. The vulnerability allows unauthorized actors to bypass intended security constraints by exploiting incorrectly configured access control security levels. This flaw affects all versions of WP Mailster from n/a through 1.9.0.0.\nThe vulnerability type is classified as a Missing Authorization issue. The impact allows for unauthorized interactions with the plugin's functionality, potentially leading to unauthorized data exposure, configuration changes, or the execution of administrative actions without valid credentials. The risk to the organization is significant, as it permits attackers with no or insufficient privileges to perform operations reserved for higher-privileged users. Exploitation does not require advanced technical skill, as it primarily involves direct manipulation of requests that lack proper server-side authorization checks.\nThe attack is viable over the network, assuming the target WP Mailster instance is reachable. Security implications include the potential for unauthorized management of email queues, subscriber data, or plugin configuration, depending on the specific backend methods left unprotected by the flawed authorization logic.",
  "technicalDetails": "The vulnerability resides within the WP Mailster core plugin logic, specifically affecting the authorization handling mechanisms for internal API endpoints or administrative action handlers. The root cause is an improper implementation of access control checks (CWE-862: Missing Authorization) where the application fails to verify the current user's role or capabilities before executing sensitive plugin operations.\nIn WP Mailster versions 1.9.0.0 and earlier, the plugin exposes functions intended for restricted user groups—such as site administrators or plugin managers—without enforcing necessary nonce checks or capability validation (e.g., current_user_can()). Because these endpoints lack server-side authorization enforcement, an attacker can craft HTTP requests targeting these specific functions.\nThe attack flow typically follows this sequence: 1) The attacker identifies the vulnerable endpoint, often by analyzing the plugin's JavaScript files or server-side PHP files for registered actions or AJAX handlers. 2) The attacker sends a crafted request (GET or POST) to the identified endpoint. 3) The backend server receives the request and executes the requested function under the assumption that the caller has already been authenticated and authorized, failing to perform an independent verification of the session's privileges. 4) The application processes the request, returning sensitive data or performing unauthorized modifications to the system state.\nThe scope of exploitation is dependent on the specific functions exposed via the vulnerable entry points. If a vulnerable function manages administrative settings, an attacker might modify plugin configurations. If the function manages subscriber databases or email queues, the attacker may be able to extract sensitive recipient lists, modify mail templates, or inject malicious content into outgoing communications. Because the vulnerability is rooted in the absence of an authorization check, the attacker does not need to bypass a login page or perform complex session hijacking; they simply interact with the unprotected functionality directly via the web server.\nThe flaw affects the entire WP Mailster plugin suite within the specified versions. Post-exploitation impact is limited only by the permissions of the functions exposed. However, in the context of WordPress plugins, missing authorization vulnerabilities often lead to full administrative compromise if the exposed functions permit configuration changes or the modification of site-wide options. There is no requirement for specific network privileges, as the exposure is typically available via the standard web interface of the WordPress installation."
}
CVE-2026-105055: WP Mailster Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere