WP Vulnerability WatchVulnerability data as of October 1, 2026

Vulnerability alerts / September 30, 2026

Vulnerability in Newsletter – Send awesome emails from WordPress — CVE-2026-92537

MediumSeverity
CVSS 5.3
—Estimated exploit probability
EPSS
200,000+ sitesInstalls
9.4.0Fixed in

What to do now

Update Newsletter – Send awesome emails from WordPress to 9.4.0 or later.

Affected versions

  • Everything up to and including 9.3.9

Affected: Newsletter – Send awesome emails from WordPress (plugin, newsletter)

Check: The plugin on wordpress.org / Our record for Newsletter – Send awesome emails from WordPress

What the vulnerability is

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=<id>-<raw_token>` response header to the requester because the subscriber object loaded via `get_user()` lacks the `_trusted` property, causing `get_user_key()` to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (`?na=px`), rewrite the subscriber's stored profile (`?na=ps`), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (`?na=ocu`), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy set — can replay it indefinitely to obtain the victim's credential.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/ed68a4ff-a2aa-4df7-96b1-f094bce4b9b7
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts