Impact
The Newsletters WordPress plugin prior to version 4.16 does not authenticate or validate bounce‑processing requests before fetching a user‑supplied URL on the server side. This mistake allows an unauthenticated actor to instruct the site to retrieve any specified host, effectively turning the server into a proxy that can reach internal resources or external destinations. The flaw can lead to accidental exposure of data, unintended interactions with other services, or the ability to pull malicious content into the site without the owner’s knowledge.
Affected Systems
All installations of the Newsletters plugin running a version earlier than 4.16, regardless of the WordPress site or hosting provider.
Risk and Exploitability
Because the vulnerability is unauthenticated, any entity able to trigger the bounce handler can exploit it. An attacker only needs to send a bounce‑processing request, which might be possible via exposed webhooks or by forging an email bounce. The CVSS score is 8.2 and the EPSS score is less than 1%, indicating a high severity but modest likelihood of exploitation. The issue is not listed in the CISA KEV catalog, yet the potential for indiscriminate HTTP communication makes it a significant concern.
OpenCVE Enrichment