Vulnerability in Newsletters, Email Marketing, SMS and Popups by Omnisend — CVE-2026-97074
MediumSeverity
—Estimated exploit probability
100,000+ sitesInstalls
1.9.1Fixed in
What to do now
Update Newsletters, Email Marketing, SMS and Popups by Omnisend to 1.9.1 or later.
Affected versions
- Everything up to and including 1.9.0
Affected: Newsletters, Email Marketing, SMS and Popups by Omnisend (plugin, omnisend)
What the vulnerability is
The Newsletters, Email Marketing, SMS and Popups by Omnisend plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.0. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.