CVE-2026-17520
Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.
| Vendor | unknown |
| Product | newsletters |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown newsletters
Be the first to know when new unknown vulnerabilities affecting unknown newsletters are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Newsletters
0 < 4.17
References
Credits
Erwan LR (WPScan) WPScan