WordPress security changelog
MEDIUM CVE-2026-86824 Deferred

Newsletter permits forged tracking links and subscriber-session access

Newsletter before 9.3.8 generates an email-tracking signing key with insufficient entropy and uses an unkeyed hash to sign tracking links. An unauthenticated attacker who first recovers that key offline can forge links to obtain a subscriber session token, then read and change the subscriber's stored personal data. The export does not disclose the recovery inputs, hash algorithm, link parameters or callback. The described session is a Newsletter subscriber session, not proof of WordPress administrator-login access.

CVE / CNA score 4.8 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
Newsletter
Plugin slug
newsletter
Affected
< 9.3.8
Safe version
9.3.8
Published
Sep 17, 2026
Weakness
CWE-326 — Inadequate Encryption Strength

This CVE was published Sep 17, 2026 and is one of 21 known issues for this plugin.

Update, patch or deactivate.

Update Newsletter to 9.3.8 or later. Use a cryptographically random signing key and a keyed message-authentication code, bind tokens to their intended subscriber and action, and expire them appropriately. Rotate weak keys and invalidate affected tracking/session tokens after updating.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.

CVE / CNA vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Primary and upstream sources