
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1831 is a Missing Authorization vulnerability in the YayMail – WooCommerce Email Customizer plugin for WordPress that allows authenticated attackers to install and activate the YaySMTP plugin without proper authorization. All versions up to and including 4.3.2 are affected. The vulnerability was published on February 18, 2026, with a CVSS v3.1 base score of 2.7 (Low) (Red Hat CVE).
The root cause is a Missing Authorization flaw (CWE-862) — specifically, the absence of capability checks on two endpoints: the yaymail_install_yaysmtp AJAX action and the /yaymail/v1/addons/activate REST API endpoint. An authenticated attacker with Shop Manager-level access or higher can send crafted requests to these endpoints to trigger unauthorized installation and activation of the YaySMTP plugin. Because no authorization validation is performed, the plugin installation proceeds as if the request were legitimate (Red Hat CVE).
Successful exploitation allows an authenticated Shop Manager (or higher privilege) to install and activate the YaySMTP plugin on the target WordPress site without administrative approval. This could enable an attacker to reconfigure outbound email settings (e.g., redirecting transactional emails through an attacker-controlled SMTP server), potentially leading to credential harvesting, email interception, or further privilege escalation if the installed plugin introduces additional attack surface. Confidentiality and availability impacts are rated as none, with only a low integrity impact (Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Shop Manager level or above, significantly limiting the attacker pool (Red Hat CVE).
yaymail_install_yaysmtp AJAX action (e.g., POST /wp-admin/admin-ajax.php?action=yaymail_install_yaysmtp) with a valid WordPress nonce for the authenticated session./yaymail/v1/addons/activate REST API endpoint to activate the newly installed YaySMTP plugin, bypassing any capability checks./wp-admin/admin-ajax.php?action=yaymail_install_yaysmtp or to the REST endpoint /wp-json/yaymail/v1/addons/activate from Shop Manager accounts./wp-content/plugins/yaysmtp/) on sites where it was not intentionally installed by an administrator.Users should update the YayMail – WooCommerce Email Customizer plugin to a version beyond 4.3.2 that includes proper capability checks on the affected AJAX action and REST endpoint. Until a patched version is available or applied, administrators should audit Shop Manager accounts for unauthorized access and consider temporarily restricting REST API access or disabling the AJAX action via a Web Application Firewall (WAF) rule. Regularly review installed plugins for unexpected additions (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."