Skip to finding
important · Zero-click email

An automatically processed email can plant PHP in an AcyMailing site’s web root.

Affects

AcyMailing Enterprise, an email-marketing extension for Joomla and WordPress websites, when mailbox actions or bounce handling use the bundled POP3 parser.

The path is limited to Enterprise installations using the bundled POP3 mailbox-action or bounce flow. A faulty MIME image test and missing extension check can write an attacker-named PHP part beneath media/com_acym/upload/.

Detail and 4 sources

Version 11.1.0 adds the checks. We do not know how often the final execution step works: it depends on PHP being enabled in the media directory, and the reporting researcher did not reproduce execution.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 27, 2026