CVE-2026-17522 PUBLISHED

Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF

Assigner: WPScan
Reserved: 27.07.2026 Published: 29.08.2026 Updated: 29.08.2026

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters WordPress plugin before 4.17 settings, including the credential protecting its API, via a Cross-Site Request Forgery attack.

Product Status

Vendor Unknown
Product Newsletters
Versions Default: unaffected
  • affected from 0 to 4.17 (excl.)

Credits

  • Erwan LR (WPScan) finder
  • WPScan coordinator

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE