CVE-2026-86823
Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end actions.
| Vendor | unknown |
| Product | newsletter |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown newsletter
Be the first to know when new unknown vulnerabilities affecting unknown newsletter are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Newsletter
0 < 9.3.7
References
Credits
Artus KG WPScan