CVE-2026-17520
Received Received - Intake

Insecure API Key Generation in Newsletters WordPress Plugin

Vulnerability report for CVE-2026-17520, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
newsletter newsletters to 4.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Newsletters WordPress plugin before version 4.17 generates its API key using a weak source, making it predictable. Attackers can compute this key and use it to perform privileged actions like managing subscribers or sending emails if the API feature is enabled.

Detection Guidance

Check the installed version of the Newsletters plugin in WordPress. If it is below 4.17, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details.

Impact Analysis

Unauthenticated attackers could add or delete subscribers, send unauthorized emails, or manipulate subscriber lists. This could lead to spam, data loss, or reputational damage if misused.

Compliance Impact

This vulnerability could lead to unauthorized access to subscriber data, violating GDPR (data protection) and HIPAA (health data privacy) by exposing personal information without consent.

Mitigation Strategies

Update the Newsletters plugin to version 4.17 or later immediately. Disable the optional API feature if not required. Monitor for unauthorized subscriber changes or email activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17520. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart