Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-17520

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Aug 29, 2026
Vendor unknown

Description

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.

References