Description
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
Published: 2026-09-30
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Data Access
Action: Patch
AI Analysis

Impact

The Omnisend WordPress plugin has an insecure direct object reference flaw that lets an attacker retrieve or manipulate subscriber information without proper authorization. This weakness allows a user with sufficient access to the plugin to target other subscribers by guessing or constructing valid identifiers, exposing sensitive data such as email addresses, phone numbers, or subscription preferences. The flaw is cataloged as CWE–639, indicating that an application "lacks sufficient restrictions on the use of internal object references."

Affected Systems

All installations of the WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin with version 1.9.0 or earlier are affected. The vulnerability applies to the plugin when installed on any WordPress site that uses it for managing subscribers and marketing communication.

Risk and Exploitability

The CVSS score of 4.3 classifies the risk as moderate, reflecting that the flaw requires the attacker to have some level of access to the plugin or site. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user of the plugin attempting to access subscriber data via manipulated URLs or API calls; exploitation requires only that the attacker can reach the plugin’s internal endpoints, which are typically exposed to site users with subscriber or higher roles.

Generated by OpenCVE AI on September 30, 2026 at 16:05 UTC.

Remediation

Vendor Solution

Update the WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin to the latest available version (at least 1.9.1).


OpenCVE Recommended Actions

  • Update the WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin to the latest available version (at least 1.9.1).
  • Limit the roles that can view or edit subscriber data by configuring WordPress user capabilities or using a role‑management plugin.

Generated by OpenCVE AI on September 30, 2026 at 16:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
Title WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin <= 1.9.0 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:27:07.547Z

Reserved: 2026-09-24T00:20:10.982Z

Link: CVE-2026-97074

cve-icon Vulnrichment

Updated: 2026-09-30T13:19:15.571Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:34.340

Modified: 2026-09-30T14:18:13.693

Link: CVE-2026-97074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key