Description
The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end actions.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect and Token Disclosure
Action: Immediate Patch
AI Analysis

Impact

The Newsletter WordPress plugin prior to version 9.3.7 fails to validate the target URL supplied during a public subscription process. This flaw allows an attacker to supply a malicious redirect URL, resulting in a user’s browser being sent to an arbitrary external site once a subscription is completed. At the same time, the plugin leaks the subscriber token associated with the new record, giving anyone who intercepts the response the ability to access that subscriber’s front‑end actions. The combined effect is a privacy breach and a vector for phishing or other social engineering attacks.

Affected Systems

Any WordPress installation that has Newsletter version 9.3.6 or earlier installed is vulnerable, regardless of site location or host. The vulnerability does not require authentication; it is triggered whenever a public subscription request is made. No specific domain data is available, but the risk applies to all publicly accessible deployments of the plugin.

Risk and Exploitability

The EPSS score of less than 1% indicates that exploitation likelihood is very low at the time of analysis, and the issue is not listed in the CISA KEV catalog. The CVSS score of 5.3 suggests moderate severity. The attack path is straightforward: an attacker creates a subscription link that points the Newsletter redirect endpoint to a chosen malicious URL. When an unsuspecting user clicks this link, the site redirects to the attacker’s domain and returns the subscriber token in the response. Because the flaw is unauthenticated, any visitor can be impacted, but practical exploitation depends on successful social‑engineering to prompt a subscription.

Generated by OpenCVE AI on September 20, 2026 at 05:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Newsletter plugin to version 9.3.7 or newer, which implements proper redirect validation and removes token disclosure.
  • If an immediate upgrade is not feasible, configure the WordPress instance to whitelist only trusted redirect destinations or strip the ncu parameter entirely, ensuring no external URLs can be supplied.
  • Monitor HTTP traffic for unexpected redirect patterns or unexpected exposure of subscriber tokens, and audit user access logs for unusually frequent or suspicious subscriber‑record activity.

Generated by OpenCVE AI on September 20, 2026 at 05:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-601

Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Newsletter
Newsletter newsletter
Wordpress
Wordpress wordpress
Vendors & Products Newsletter
Newsletter newsletter
Wordpress
Wordpress wordpress

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end actions.
Title Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter
References

Subscriptions

Newsletter Newsletter
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:33:42.412Z

Reserved: 2026-09-08T14:20:35.409Z

Link: CVE-2026-86823

cve-icon Vulnrichment

Updated: 2026-09-17T12:16:04.217Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:35.043

Modified: 2026-09-17T13:16:54.037

Link: CVE-2026-86823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:30:16Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')