Impact
The vulnerability arises because the Newsletter plugin before version 9.3.8 uses a tracking signing key that is not generated with enough entropy and employs an unkeyed hash to sign tracking links. This allows an attacker who recovers that key offline to forge tracking URLs. By interacting with forged links, the attacker can obtain any subscriber’s session token, read that subscriber’s personal data, and modify it. The vulnerability can therefore lead to unauthorized disclosure and tampering of subscriber PII.
Affected Systems
Affected systems are WordPress sites running the Newsletter plugin older than 9.3.8. No specific vendor is listed; the plugin is referred to generically as "Newsletter". Any site that uses a version prior to 9.3.8 is impacted.
Risk and Exploitability
The CVSS base score is 4.8, indicating a moderate impact. The EPSS score is less than 1 %, suggesting low likelihood of exploitation, and the vulnerability is not in the CISA KEV catalog. Attackers must first recover the weak signing key offline before they can forge tracking links; this prerequisite reduces the overall risk. If the key can be extracted, the attacker can obtain session tokens and PII without authentication, resulting in full read/write access to subscriber data.
OpenCVE Enrichment