CVE-2026-86823: Newsletter < 9.3.7 - Unauthenticated Open Redirect and Subscriber Token Disclosure via ncu Parameter
The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end actions.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker does not need to authenticate. Exploitation involves a public subscription action, so sites that expose that functionality are relevant.
What could an attacker obtain through exploitation?
The attacker can cause a redirect to an arbitrary external site and disclose a subscriber token. That token grants access to front-end actions for the affected subscriber record.
What version addresses the issue?
Upgrade the Newsletter WordPress plugin to version 9.3.7 or later. Versions before 9.3.7 are affected.