CVE-2026-97074: WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend plugin <= 1.9.0 - Insecure Direct Object References (IDOR) vulnerability
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Newsletters, Email Marketing, SMS and Popups by Omnisend pluginto a version that resolves this vulnerability.Fixed in 1.9.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges. Exploitation does not require user interaction and can be performed over the network.
What is the likely impact of successful exploitation?
The reported impact is limited to integrity, with no stated confidentiality or availability impact. The vulnerability concerns insecure direct object references involving subscribers.
Which installations are affected?
Installations using the Newsletters, Email Marketing, SMS and Popups by Omnisend plugin version 1.9.0 or earlier are identified as affected.