PT-2026-69169 · WordPress · Newsletters
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Newsletters WordPress plugin versions prior to 4.16
Description
When the optional API is enabled, the software fails to strictly compare the API authentication key. This allows unauthenticated attackers to bypass authentication using type juggling—a behavior where a language's loose comparison allows different data types to be treated as equal—to perform privileged actions, including modifying subscriber records and sending emails.
Recommendations
Update the Newsletters WordPress plugin to version 4.16 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Newsletters