CVE-2026-16264: Newsletters < 4.18.1 - Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOR
The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites running the Tribulant Newsletters WordPress plugin before version 4.18.1 are exposed. The affected subscriber-management actions can be reached by unauthenticated visitors.
What does an attacker need to exploit it?
An attacker does not need an authenticated WordPress account. They can request a management session and exploit missing ownership checks on subscriber-management actions.
What could an attacker do with a successful exploit?
An attacker can read personal data for any subscriber and overwrite subscriber records, including changing a subscriber's email address.
What is the remediation?
Update the Newsletters plugin to version 4.18.1 or later. The issue affects versions before 4.18.1.