CVE-2026-16264
Received Received - Intake

Unauthenticated Subscriber Data Manipulation in Newsletters WordPress Plugin

Vulnerability report for CVE-2026-16264, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
newsletter_plugin newsletters to 4.18.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Newsletters WordPress plugin versions before 4.18.1. It is an Insecure Direct Object Reference (IDOR) flaw where the plugin fails to verify ownership during subscriber management actions. Unauthenticated attackers can exploit this to overwrite subscriber records, including changing email addresses, and access personally identifiable information (PII) of any subscriber.

Detection Guidance

Check if your WordPress site uses the Newsletters plugin version prior to 4.18.1. Log in as a subscriber and attempt to access subscriber management actions without proper authentication. Review server logs for unusual requests to subscriber endpoints.

Impact Analysis

If you use the affected plugin, attackers could gain access to subscriber data, modify email addresses, and potentially impersonate subscribers. This could lead to data breaches, unauthorized access to accounts, and misuse of personal information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA due to unauthorized access and disclosure of personal data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A breach could result in legal penalties and reputational damage.

Mitigation Strategies

Update the Newsletters plugin to version 4.18.1 or later immediately. Disable any subscriber management features if not essential. Monitor subscriber records for unauthorized changes to email addresses or personal data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16264. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart