Impact
The Newsletters WordPress plugin (< 4.17) lacks required nonce or capability checks when saving settings, allowing an attacker to craft a malicious request that an authenticated administrator will unknowingly process. This CSRF flaw writes every submitted parameter into the plugin's options, making it possible to overwrite arbitrary settings, including the API credential that protects the plugin's backend services.
Affected Systems
Affected systems are WordPress installations that have the Newsletters plugin installed at any version lower than 4.17, specifically 4.16 and earlier. No other plugins or WordPress versions are affected as stated by the vendor data.
Risk and Exploitability
Exploitability depends on the administrator logging into WordPress and visiting a malicious site that triggers the hidden request. The absence of a documented EPSS score and KEV listing suggests low public exploitation activity, but the impact of credential compromise is high. Administrators should update immediately, as the vulnerability allows complete control of the plugin's configuration without authentication beyond the logged‑in session.
OpenCVE Enrichment