The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.
Metrics
Affected Vendors & Products
References
History
Sun, 30 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-326 | |
| Metrics |
cvssV3_1
|
Sat, 29 Aug 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-330 |
Sat, 29 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled. | |
| Title | Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-08-29T06:00:19.539Z
Updated: 2026-08-30T00:56:53.189Z
Reserved: 2026-07-27T08:15:32.720Z
Link: CVE-2026-17520
Updated: 2026-08-30T00:49:55.747Z
Status : Deferred
Published: 2026-08-29T06:17:12.177
Modified: 2026-08-31T20:14:36.250
Link: CVE-2026-17520
No data.