CVE-2026-78146
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Aug 26, 2026
Vendor
unknown
Description
The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.