Title: Vulnerability
Last modified: September 13, 2026

---

# Vulnerability

 *  [shelleyweb](https://wordpress.org/support/users/espressivo/)
 * (@espressivo)
 * [2 weeks, 4 days ago](https://wordpress.org/support/topic/vulnerability-180/)
 * Hi team,
 * Patchstack published CVE-2026-81783 on Sept 10, a Subscriber Broken Authentication
   issue affecting MailMunch – Grow your Email List in all versions up to and including
   3.2.5. Advisory here:
 * [https://patchstack.com/database/wordpress/plugin/mailmunch/vulnerability/wordpress-mailmunch-grow-your-email-list-plugin-3-2-5-broken-authentication-vulnerability](https://patchstack.com/database/wordpress/plugin/mailmunch/vulnerability/wordpress-mailmunch-grow-your-email-list-plugin-3-2-5-broken-authentication-vulnerability)
 * It’s rated CVSS 7.1 (High), CWE-288, vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/
   C:N/I:L/A:H. As of today, 3.2.5 is still the current release on the WordPress.
   org directory, so there’s no update available to resolve it.
 * I manage a number of sites running this plugin and I’d like to know:
    1. Is a fixed release in progress, and is there a rough timeline?
    2. In the meantime, is there a recommended interim mitigation from your side (a
       setting to change, or a specific configuration that reduces exposure)?
 * For context, I noticed 3.2.2 addressed an earlier CVE (CVE-2026-7520) fairly 
   quickly with capability and nonce checks, so I’m hopeful this one is on the radar
   too. Any update would help me decide whether to hold for the patch or temporarily
   deactivate.
 * Thanks!

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fvulnerability-180%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/mailmunch/assets/icon-256x256.png?rev=1198834)
 * [MailMunch - Grow your Email List](https://wordpress.org/plugins/mailmunch/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/mailmunch/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/mailmunch/)
 * [Active Topics](https://wordpress.org/support/plugin/mailmunch/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/mailmunch/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/mailmunch/reviews/)

 * 0 replies
 * 1 participant
 * Last reply from: [shelleyweb](https://wordpress.org/support/users/espressivo/)
 * Last activity: [2 weeks, 4 days ago](https://wordpress.org/support/topic/vulnerability-180/)
 * Status: not resolved