CVE-2026-42668: Omnisend Email Marketing WooCommerce Authentication Bypass (CVSS 7.5)
The Email Marketing for WooCommerce plugin by Omnisend contains a critical authentication bypass vulnerability affecting versions 1.18.0 and earlier. An unauthenticated attacker can access sensitive email marketing functionality without valid credentials, potentially exposing customer data and campaign information. This vulnerability requires no user interaction and can be exploited remotely by any threat actor with network access to an affected WooCommerce store.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-288
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-42668 is a broken authentication vulnerability (CWE-288) in the Omnisend Email Marketing for WooCommerce plugin versions up to and including 1.18.0. The vulnerability allows unauthenticated access to protected API endpoints or administrative functions related to email marketing operations. The attack vector is network-based with low attack complexity, meaning the flaw can be exploited directly without requiring special conditions, elevated privileges, or user interaction. The CVSS 3.1 score of 7.5 (HIGH) reflects the high confidentiality impact—attackers can read sensitive email marketing data, customer contact lists, campaign configurations, and potentially personally identifiable information—without the ability to modify or delete data from the perspective of this CVE's scoring.
Business impact
Organizations using the Omnisend Email Marketing plugin may face exposure of customer email addresses, marketing campaign details, subscriber preferences, and potentially sensitive business intelligence. Depending on data stored within the plugin, this could include GDPR-regulated personal data, creating compliance obligations. Reputational harm, regulatory fines, and breach notification costs are realistic consequences. If attackers gain access to email campaign infrastructure, they could leverage that foothold for further lateral movement within the WooCommerce environment or associated WordPress systems.
Affected systems
Any WooCommerce installation with the Email Marketing for WooCommerce plugin by Omnisend version 1.18.0 or earlier is affected. This includes self-hosted WordPress sites using WooCommerce as an e-commerce platform. Organizations running outdated or unpatched instances of the plugin are at immediate risk. The vulnerability does not appear to be limited by specific WordPress versions or WooCommerce configurations based on available information.
Exploitability
This vulnerability has a low barrier to exploitation. No authentication is required, no user interaction is necessary, and the attack can be performed over the network. An attacker needs only knowledge that an affected Omnisend plugin is active on a target WooCommerce store and can craft direct API requests to bypass authentication controls. Given the straightforward nature of broken authentication flaws, exploitation is technically straightforward and does not require advanced capabilities or zero-day techniques.
Remediation
Immediately update the Email Marketing for WooCommerce plugin by Omnisend to a version newer than 1.18.0. Administrators should verify the latest patched version against the official Omnisend plugin repository or the vendor's security advisories. As an interim mitigation, consider disabling or deactivating the plugin if immediate patching is not possible, though this may impact email marketing operations. Review access logs and API activity within the plugin for signs of unauthorized access following the vulnerability publication date.
Patch guidance
Update the Omnisend Email Marketing for WooCommerce plugin to the latest available version beyond 1.18.0 by navigating to Plugins > Installed Plugins in the WordPress admin dashboard and clicking 'Update' next to the Omnisend plugin. Verify the new version number against the official Omnisend plugin page or security advisory to confirm you are installing a patched release. Test the plugin's email marketing functionality after updating to ensure no configuration or data loss occurred. If automatic updates are enabled, ensure they have completed successfully.
Detection guidance
Monitor WooCommerce and WordPress access logs for unusual API requests to email marketing endpoints, particularly those originating from unexpected IP addresses or showing patterns inconsistent with normal administrative activity. Check plugin access logs for unauthenticated requests to functions or endpoints that should require authentication. Utilize Web Application Firewall (WAF) rules to detect or block suspicious requests to the Omnisend plugin's known API paths. Security Information and Event Management (SIEM) systems can correlate authentication bypass attempts across multiple requests or time periods. Verify the installed plugin version regularly through WordPress admin dashboards or automated scanning tools.
Why prioritize this
This vulnerability merits immediate attention due to its high CVSS score, ease of exploitation, and the sensitive nature of email marketing data. The lack of authentication requirements combined with high confidentiality impact means any attacker on the internet can potentially access customer data without technical barriers. While not yet flagged in the CISA KEV catalog, the vulnerability's straightforward nature makes active exploitation likely once public disclosure is complete. Organizations handling customer PII through email marketing should treat this as critical.
Risk score, explained
The CVSS 3.1 score of 7.5 (HIGH) is justified by the network attack vector (AV:N), low attack complexity (AC:L), no privilege requirements (PR:N), no user interaction needed (UI:N), and high confidentiality impact (C:H). The attack scope is unchanged (S:U), meaning the impact is confined to the vulnerable component. While integrity and availability are not directly impacted (I:N, A:N), the unauthorized disclosure of sensitive customer and business data creates significant organizational and regulatory risk. The high score reflects the ease and impact of exploitation despite the absence of direct data modification or service disruption.
Frequently asked questions
Does this vulnerability allow attackers to modify or delete email campaigns?
Based on the CVSS scoring, this vulnerability results in unauthorized information disclosure (confidentiality impact) rather than modification or deletion of data (integrity impact). However, attackers could potentially perform further actions depending on the specific implementation within the plugin. Organizations should verify the scope of accessible functions through the vendor's detailed advisory.
Is there a public exploit available for CVE-2026-42668?
This vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog as of the current date. However, the straightforward nature of authentication bypass vulnerabilities typically leads to proof-of-concept publication and active exploitation within days of disclosure. Monitor threat intelligence feeds and the vendor's security page for updates.
Can a Web Application Firewall (WAF) protect against this vulnerability?
A WAF may provide temporary protection by blocking requests to known vulnerable endpoints, but it is not a substitute for patching. WAF rules must be tailored to your Omnisend plugin configuration and kept current. The most effective mitigation is updating the plugin itself.
What customer data is at risk if our store is compromised?
At minimum, email subscriber lists and marketing campaign configurations are exposed. Depending on how the Omnisend plugin integrates with WooCommerce, customer email addresses, purchase history, behavior data, and preferences may be accessible. Review the plugin's data storage and access controls in your installation to determine your specific exposure.
This analysis is provided for informational purposes to help security leaders understand and respond to CVE-2026-42668. The vulnerability details, affected versions, and CVSS score are based on official CVE records as of the publication date. Specific patch versions, detailed technical analysis, and vendor-specific remediation steps should be verified against the official Omnisend security advisory and WooCommerce plugin repository. Organizations should conduct their own testing and risk assessment based on their specific environment and data exposure. This report does not constitute legal or compliance advice; consult your legal and compliance teams regarding breach notification obligations or regulatory requirements related to any data exposure. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-40780HIGHBookIt Authentication Bypass via Password Recovery
- CVE-2026-42654HIGHWP Swings Wallet System Authentication Bypass Allows Account Takeover
- CVE-2026-5415HIGHWP Captcha PRO Authentication Bypass — Full Account Takeover Risk
- CVE-2026-8697HIGHTP-Link Archer C64 Unauthenticated Brute-Force SSH Vulnerability
- CVE-2026-36175MEDIUMGNCC GP5 Physical Authentication Bypass via U-Boot Boot Arguments
- CVE-2026-47200MEDIUMNuxt Component Islands Route Middleware Bypass
- CVE-2016-20062HIGHSQL Injection in Simply Poll 1.4.1 WordPress Plugin - Unauthenticated Data Theft
- CVE-2016-20063HIGHSQL Injection in Single Personal Message 1.0.3 – Credential & Data Theft Risk