Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-1938
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1938 is a missing authorization vulnerability in the YayMail – WooCommerce Email Customizer plugin for WordPress that allows authenticated attackers to delete the plugin's license key without proper authorization checks. It affects plugin versions up to and including 4.3.2, targeting the /yaymail-license/v1/license/delete REST API endpoint. The vulnerability was published on February 18, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).

Technical details

The root cause is a missing authorization check (CWE-862) on the /yaymail-license/v1/license/delete REST endpoint in the YayMail plugin. An authenticated attacker with Shop Manager-level access or higher can send a crafted DELETE request to this endpoint, provided they can obtain a valid REST API nonce, to remove the plugin's license key. No additional preconditions beyond authenticated Shop Manager access and nonce acquisition are required (Red Hat CVE).

Impact

Successful exploitation allows an authenticated attacker to delete the YayMail plugin's license key, effectively disrupting the plugin's licensed functionality and potentially disabling WooCommerce email customization features on the affected WordPress site. The impact is limited to integrity (no confidentiality or availability impact), and there is no evidence of lateral movement potential or sensitive data exposure associated with this vulnerability (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-1938. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Red Hat CVE).

Exploitation steps

  1. Authenticate: Log in to the target WordPress site with a Shop Manager-level account or higher.
  2. Obtain REST API nonce: Retrieve a valid WordPress REST API nonce, typically by making an authenticated request to the WordPress admin or via the wp-admin/admin-ajax.php endpoint.
  3. Send DELETE request: Issue an HTTP DELETE (or equivalent) request to the /yaymail-license/v1/license/delete REST endpoint, including the obtained nonce in the request headers or parameters.
  4. License key deleted: Due to the missing authorization check, the server processes the request and deletes the YayMail plugin's license key, disrupting licensed plugin functionality (Red Hat CVE).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated DELETE or POST requests to /wp-json/yaymail-license/v1/license/delete from unexpected user accounts or IP addresses.
  • Application: YayMail plugin license key missing or deactivated unexpectedly in the WordPress admin panel without administrator action.
  • Logs: WordPress audit logs (if enabled) recording license deletion events attributed to Shop Manager accounts at unusual times.

Mitigation and workarounds

Users should update the YayMail – WooCommerce Email Customizer plugin to a version beyond 4.3.2 that includes a proper authorization check on the license deletion endpoint. As a temporary workaround, administrators can restrict Shop Manager role capabilities or monitor REST API access logs for suspicious requests to the license endpoint. Limiting the number of accounts with Shop Manager access reduces the attack surface (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86801HIGH8.8
  • todo-lists-for-membership-sites
NoNoSep 17, 2026
CVE-2026-87963HIGH8.6
  • yo
NoNoSep 17, 2026
CVE-2026-91016MEDIUM5.3
  • motors-car-dealership-classified-listings
NoYesSep 17, 2026
CVE-2026-91019MEDIUM4.9
  • mage-eventpress
NoYesSep 17, 2026
CVE-2026-91017LOW3.7
  • robokassa
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management