CVE-2026-16264 PUBLISHED

Newsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOR

Assigner: WPScan
Reserved: 20.07.2026 Published: 23.09.2026 Updated: 23.09.2026

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.

Product Status

Vendor Unknown
Product Newsletters
Versions Default: unaffected
  • affected from 0 to 4.18.1 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE