CVE-2026-1831
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1831 is a Missing Authorization vulnerability in the YayMail – WooCommerce Email Customizer plugin for WordPress that allows authenticated attackers to install and activate the YaySMTP plugin without proper authorization. All versions up to and including 4.3.2 are affected. The vulnerability was published on February 18, 2026, with a CVSS v3.1 base score of 2.7 (Low) (Red Hat CVE).

Technical details

The root cause is a Missing Authorization flaw (CWE-862) — specifically, the absence of capability checks on two endpoints: the yaymail_install_yaysmtp AJAX action and the /yaymail/v1/addons/activate REST API endpoint. An authenticated attacker with Shop Manager-level access or higher can send crafted requests to these endpoints to trigger unauthorized installation and activation of the YaySMTP plugin. Because no authorization validation is performed, the plugin installation proceeds as if the request were legitimate (Red Hat CVE).

Impact

Successful exploitation allows an authenticated Shop Manager (or higher privilege) to install and activate the YaySMTP plugin on the target WordPress site without administrative approval. This could enable an attacker to reconfigure outbound email settings (e.g., redirecting transactional emails through an attacker-controlled SMTP server), potentially leading to credential harvesting, email interception, or further privilege escalation if the installed plugin introduces additional attack surface. Confidentiality and availability impacts are rated as none, with only a low integrity impact (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Shop Manager level or above, significantly limiting the attacker pool (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify a WordPress site running the YayMail – WooCommerce Email Customizer plugin version 4.3.2 or earlier, and obtain or compromise a Shop Manager-level (or higher) account.
  2. Trigger unauthorized plugin installation: Send an authenticated POST request to the yaymail_install_yaysmtp AJAX action (e.g., POST /wp-admin/admin-ajax.php?action=yaymail_install_yaysmtp) with a valid WordPress nonce for the authenticated session.
  3. Activate the plugin via REST endpoint: Send an authenticated POST request to the /yaymail/v1/addons/activate REST API endpoint to activate the newly installed YaySMTP plugin, bypassing any capability checks.
  4. Leverage installed plugin: Once YaySMTP is active, configure it (if permissions allow) to route outbound WordPress emails through an attacker-controlled SMTP server, enabling email interception or credential harvesting (Red Hat CVE).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to /wp-admin/admin-ajax.php?action=yaymail_install_yaysmtp or to the REST endpoint /wp-json/yaymail/v1/addons/activate from Shop Manager accounts.
  • File System: Unexpected presence of the YaySMTP plugin directory (/wp-content/plugins/yaysmtp/) on sites where it was not intentionally installed by an administrator.
  • Logs: WordPress debug or activity logs recording plugin installation/activation events attributed to a Shop Manager user rather than an Administrator.
  • Network: Outbound SMTP connections to unfamiliar or external mail servers originating from the WordPress host after YaySMTP activation.

Mitigation and workarounds

Users should update the YayMail – WooCommerce Email Customizer plugin to a version beyond 4.3.2 that includes proper capability checks on the affected AJAX action and REST endpoint. Until a patched version is available or applied, administrators should audit Shop Manager accounts for unauthorized access and consider temporarily restricting REST API access or disabling the AJAX action via a Web Application Firewall (WAF) rule. Regularly review installed plugins for unexpected additions (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83547MEDIUM6.8
  • xpro-elementor-addons
NoYesSep 02, 2026
CVE-2026-82884MEDIUM6.8
  • all-in-one-seo-pack
NoYesSep 02, 2026
CVE-2026-8151MEDIUM5.4
  • simple-membership-mailchimp-integration
NoYesSep 02, 2026
CVE-2026-83533MEDIUM5.3
  • wp-express-checkout
NoYesSep 02, 2026
CVE-2026-81571MEDIUM4.8
  • brave-popup-builder
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management