Newsletter permits forged tracking links and subscriber-session access
Newsletter before 9.3.8 generates an email-tracking signing key with insufficient entropy and uses an unkeyed hash to sign tracking links. An unauthenticated attacker who first recovers that key offline can forge links to obtain a subscriber session token, then read and change the subscriber's stored personal data. The export does not disclose the recovery inputs, hash algorithm, link parameters or callback. The described session is a Newsletter subscriber session, not proof of WordPress administrator-login access.
- Component
- Newsletter
- Plugin slug
newsletter- Affected
- < 9.3.8
- Safe version
9.3.8- Published
- Sep 17, 2026
This CVE was published Sep 17, 2026 and is one of 21 known issues for this plugin.
Update, patch or deactivate.
Update Newsletter to 9.3.8 or later. Use a cryptographically random signing key and a keyed message-authentication code, bind tokens to their intended subscriber and action, and expire them appropriately. Rotate weak keys and invalidate affected tracking/session tokens after updating.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify that subscriber's stored personal data.
CVE / CNA vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N