CVE Database /
CVE-2026-2515
CVE · Medium
CVE-2026-2515 — Hostinger Reach – AI-Powered Email Marketing for WordPress [hostinger-reach] < 1.3.9
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-2515
|
Hostinger Reach – AI-Powered Email Marketing for WordPress [hostinger-reach] < 1.3.9 |
Missing Authorization |
Medium
5.3
|
< 1.3.9
|
1.3.9 |
2026-05-12 |
—
|
CVE-2026-2515
The Hostinger Reach email marketing plugin for WordPress contains a security flaw that allows attackers with Subscriber-level access or higher to secretly alter data within the plugin's database. This issue arises from an oversight in the 'handle_ajax_action' function, which fails to verify user permissions before allowing certain actions to be performed. The vulnerability can only be exploited under specific circumstances: when the plugin is not linked to a site and no API key has been stored in the database.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings