Impact
The Omnisend WordPress plugin has an insecure direct object reference flaw that lets an attacker retrieve or manipulate subscriber information without proper authorization. This weakness allows a user with sufficient access to the plugin to target other subscribers by guessing or constructing valid identifiers, exposing sensitive data such as email addresses, phone numbers, or subscription preferences. The flaw is cataloged as CWE–639, indicating that an application "lacks sufficient restrictions on the use of internal object references."
Affected Systems
All installations of the WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin with version 1.9.0 or earlier are affected. The vulnerability applies to the plugin when installed on any WordPress site that uses it for managing subscribers and marketing communication.
Risk and Exploitability
The CVSS score of 4.3 classifies the risk as moderate, reflecting that the flaw requires the attacker to have some level of access to the plugin or site. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user of the plugin attempting to access subscriber data via manipulated URLs or API calls; exploitation requires only that the attacker can reach the plugin’s internal endpoints, which are typically exposed to site users with subscriber or higher roles.
OpenCVE Enrichment