CVE-2026-86823
N/A
N/A
Summary
The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect users to arbitrary external sites and to disclose a subscriber token that grants access to that subscriber record's front-end actions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Newsletter | 0 < 9.3.7 | affected |
Weaknesses
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.