CVE-2026-86824 PUBLISHED

Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key

Assigner: WPScan
Reserved: 08.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.

Product Status

Vendor Unknown
Product Newsletter
Versions Default: unaffected
  • affected from 0 to 9.3.8 (excl.)

Credits

  • Karthik Ramakrishnan finder
  • WPScan coordinator

References

Problem Types

  • CWE-326 Inadequate Encryption Strength CWE