Description
The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.
Published: 2026-09-17
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data disclosure and modification of subscriber PII via forged tracking links
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises because the Newsletter plugin before version 9.3.8 uses a tracking signing key that is not generated with enough entropy and employs an unkeyed hash to sign tracking links. This allows an attacker who recovers that key offline to forge tracking URLs. By interacting with forged links, the attacker can obtain any subscriber’s session token, read that subscriber’s personal data, and modify it. The vulnerability can therefore lead to unauthorized disclosure and tampering of subscriber PII.

Affected Systems

Affected systems are WordPress sites running the Newsletter plugin older than 9.3.8. No specific vendor is listed; the plugin is referred to generically as "Newsletter". Any site that uses a version prior to 9.3.8 is impacted.

Risk and Exploitability

The CVSS base score is 4.8, indicating a moderate impact. The EPSS score is less than 1 %, suggesting low likelihood of exploitation, and the vulnerability is not in the CISA KEV catalog. Attackers must first recover the weak signing key offline before they can forge tracking links; this prerequisite reduces the overall risk. If the key can be extracted, the attacker can obtain session tokens and PII without authentication, resulting in full read/write access to subscriber data.

Generated by OpenCVE AI on September 18, 2026 at 01:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Newsletter plugin to version 9.3.8 or later, which includes a properly seeded cryptographic key for link signing.
  • If upgrading is not immediately possible, disable or remove the plugin’s tracking link functionality to prevent link forgery.
  • Monitor user sessions and subscriber records for abnormal activity, such as unauthorized token usage or unexpected data changes, and enforce stricter access controls.

Generated by OpenCVE AI on September 18, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Newsletter
Newsletter newsletter
Wordpress
Wordpress wordpress
Vendors & Products Newsletter
Newsletter newsletter
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-326
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.
Title Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key
References

Subscriptions

Newsletter Newsletter
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:28:59.722Z

Reserved: 2026-09-08T14:21:27.392Z

Link: CVE-2026-86824

cve-icon Vulnrichment

Updated: 2026-09-17T12:12:07.115Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:51.663

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-86824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength