PT-2026-103661 · Satollo · Newsletter – Send Awesome Emails From Wordpress
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route
/tnp/l/ is registered with permission callback => ' return true' and, upon receiving a valid keyed-MD5 signature, calls set user cookie(), which emits a Set-Cookie: newsletter=<id>-<raw token> response header to the requester because the subscriber object loaded via get user() lacks the trusted property, causing get user key() to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (?na=px), rewrite the subscriber's stored profile (?na=ps), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (?na=ocu), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy set — can replay it indefinitely to obtain the victim's credential.Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Newsletter – Send Awesome Emails From Wordpress