Vulnerability
-
Hi team,
Patchstack published CVE-2026-81783 on Sept 10, a Subscriber Broken Authentication issue affecting MailMunch – Grow your Email List in all versions up to and including 3.2.5. Advisory here:
It’s rated CVSS 7.1 (High), CWE-288, vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H. As of today, 3.2.5 is still the current release on the WordPress.org directory, so there’s no update available to resolve it.
I manage a number of sites running this plugin and I’d like to know:
- Is a fixed release in progress, and is there a rough timeline?
- In the meantime, is there a recommended interim mitigation from your side (a setting to change, or a specific configuration that reduces exposure)?
For context, I noticed 3.2.2 addressed an earlier CVE (CVE-2026-7520) fairly quickly with capability and nonce checks, so I’m hopeful this one is on the radar too. Any update would help me decide whether to hold for the patch or temporarily deactivate.
Thanks!
You must be logged in to reply to this topic.