PT-2026-97167 · WordPress · Email Subscribers & Newsletters
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Email Subscribers & Newsletters WordPress plugin versions prior to 5.9.35
Description
The plugin fails to verify the per-subscriber management token when modifying a subscriber's subscription status. This allows unauthenticated users to force-unsubscribe or force-confirm any subscriber if the attacker knows the target's email address.
Recommendations
Update the plugin to version 5.9.35 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Email Subscribers & Newsletters