CVE-2026-17522
Received Received - Intake

Unauthenticated CSRF in Newsletters WordPress Plugin

Vulnerability report for CVE-2026-17522, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters WordPress plugin before 4.17 settings, including the credential protecting its API, via a Cross-Site Request Forgery attack.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
newsletter newsletters to 4.17 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin Newsletters before version 4.17. It allows attackers to perform Cross-Site Request Forgery (CSRF) attacks to overwrite arbitrary plugin settings without proper authorization. The plugin fails to check for nonce or capability validation when saving settings, enabling logged-in administrators to be tricked into changing critical options, including API credentials.

Detection Guidance

Check the installed version of the Newsletters WordPress plugin. If it is below 4.17, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

Attackers could exploit this to modify plugin settings, potentially disabling security features or stealing sensitive data like API credentials. If an administrator is tricked into clicking a malicious link, the attacker could gain control over the plugin's functionality, leading to unauthorized access or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements or HIPAA's security rules. If exploited, it may result in unauthorized disclosure of personal or health data, leading to legal penalties and compliance failures.

Mitigation Strategies

Update the Newsletters plugin to version 4.17 or later immediately. Remove unnecessary admin privileges and review plugin settings for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17522. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart