CVE-2026-92537 PUBLISHED

Newsletter <= 9.3.9 - Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure)

Assigner: Wordfence
Reserved: 16.09.2026 Published: 01.10.2026 Updated: 01.10.2026

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route /tnp/l/ is registered with permission_callback => '__return_true' and, upon receiving a valid keyed-MD5 signature, calls set_user_cookie(), which emits a Set-Cookie: newsletter=<id>-<raw_token> response header to the requester because the subscriber object loaded via get_user() lacks the _trusted property, causing get_user_key() to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (?na=px), rewrite the subscriber's stored profile (?na=ps), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (?na=ocu), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy set — can replay it indefinitely to obtain the victim's credential.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor satollo
Product Newsletter – Send awesome emails from WordPress
Versions Default: unaffected
  • affected from 0 to 9.3.9 (incl.)

Credits

  • Swayam finder

References

Problem Types

  • CWE-522 Insufficiently Protected Credentials CWE