medium · CVSS v3 5.3 · EPSS 0.00186
CVE-2026-83555
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token b…
Description
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 5.3
- CVSS v4
- —
- EPSS
- 0.00186