rootpwn

medium · CVSS v3 6.5 · EPSS 0.0018

CVE-2026-16264

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management …

Description

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.5
CVSS v4
EPSS
0.0018

← All CVEs