PT-2026-81271 · WordPress · Newsletters

·

CVE-2026-75908

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Newsletters versions prior to 4.18
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with author-level access or higher can send arbitrary newsletter emails to users of any WordPress role, including administrators. This is achieved by forging POST fields during a standard post submission, where an attacker-supplied role slug via the newsletters mailinglistsroles POST field is passed directly to the get users() function. This flaw enables unauthorized mass-mailing and potential phishing against privileged users using the site's own outbound email channel.
Recommendations Update Newsletters to version 4.18 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75908

Affected Products

Newsletters