
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1938 is a missing authorization vulnerability in the YayMail – WooCommerce Email Customizer plugin for WordPress that allows authenticated attackers to delete the plugin's license key without proper authorization checks. It affects plugin versions up to and including 4.3.2, targeting the /yaymail-license/v1/license/delete REST API endpoint. The vulnerability was published on February 18, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).
The root cause is a missing authorization check (CWE-862) on the /yaymail-license/v1/license/delete REST endpoint in the YayMail plugin. An authenticated attacker with Shop Manager-level access or higher can send a crafted DELETE request to this endpoint, provided they can obtain a valid REST API nonce, to remove the plugin's license key. No additional preconditions beyond authenticated Shop Manager access and nonce acquisition are required (Red Hat CVE).
Successful exploitation allows an authenticated attacker to delete the YayMail plugin's license key, effectively disrupting the plugin's licensed functionality and potentially disabling WooCommerce email customization features on the affected WordPress site. The impact is limited to integrity (no confidentiality or availability impact), and there is no evidence of lateral movement potential or sensitive data exposure associated with this vulnerability (Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-1938. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Red Hat CVE).
wp-admin/admin-ajax.php endpoint./yaymail-license/v1/license/delete REST endpoint, including the obtained nonce in the request headers or parameters./wp-json/yaymail-license/v1/license/delete from unexpected user accounts or IP addresses.Users should update the YayMail – WooCommerce Email Customizer plugin to a version beyond 4.3.2 that includes a proper authorization check on the license deletion endpoint. As a temporary workaround, administrators can restrict Shop Manager role capabilities or monitor REST API access logs for suspicious requests to the license endpoint. Limiting the number of accounts with Shop Manager access reduces the attack surface (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."