CVE-2026-86824: Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key
The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
WordPress sites using the Newsletter plugin in versions before 9.3.8 are affected. The issue is in the plugin's email-tracking signing mechanism.
Does exploitation require an authenticated WordPress account?
No. An attacker can exploit the issue without authentication after recovering the predictable tracking signing key offline.
What can an attacker do with a forged tracking link?
A forged link can provide a subscriber's session token, allowing the attacker to read and modify that subscriber's stored personal data.
What is the immediate mitigation if updating is not possible?
The provided information does not identify a workaround. Updating the Newsletter plugin to 9.3.8 or later is the indicated remediation.