medium · CVSS v3 6.5 · EPSS 0.0018
CVE-2026-16264
The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management …
Description
The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- 0.0018