Impact
The Newsletters WordPress plugin prior to version 4.18.1 fails to verify ownership when performing subscriber management actions and provides a management session to unauthenticated users. This flaw allows an attacker to read any subscriber's personal data and overwrite subscriber records, including email addresses. The underlying weakness is an improper access control that enables unauthorized disclosure and modification of data.
Affected Systems
WordPress sites running the Newsletters plugin on any version earlier than 4.18.1 are affected. No other vendors or products are specifically identified.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability presents a moderate severity risk. EPSS data is unavailable and the flaw is not listed in the CISA KEV catalog. The likely attack vector is web-based: unauthenticated users can send crafted HTTP requests to the plugin’s subscriber endpoints to gain a privileged session and manipulate subscriber records. No additional system compromises or authentication are required beyond network access to the site.
OpenCVE Enrichment