CVE · Medium

CVE-2026-2515 — Hostinger Reach – AI-Powered Email Marketing for WordPress [hostinger-reach] < 1.3.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2515 Hostinger Reach – AI-Powered Email Marketing for WordPress [hostinger-reach] < 1.3.9 Missing Authorization Medium 5.3 < 1.3.9 1.3.9 2026-05-12

CVE-2026-2515

The Hostinger Reach email marketing plugin for WordPress contains a security flaw that allows attackers with Subscriber-level access or higher to secretly alter data within the plugin's database. This issue arises from an oversight in the 'handle_ajax_action' function, which fails to verify user permissions before allowing certain actions to be performed. The vulnerability can only be exploited under specific circumstances: when the plugin is not linked to a site and no API key has been stored in the database.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.