PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75908 contrid CVE debrief

The Newsletters plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 4.17. This allows authenticated attackers with author-level access and above to send arbitrary newsletter emails to users of any WordPress role, including administrators, by forging POST fields during a normal post submission. The vulnerability enables unauthorized mass-mailing and potential phishing against privileged site users through the site's own outbound email channel, highlighting the need for immediate patching or mitigation.

Vendor
contrid
Product
Newsletters
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-25
Original CVE updated
2026-09-28
Advisory published
2026-08-25
Advisory updated
2026-09-28

Who should care

WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent unauthorized mass-mailing and potential phishing against privileged site users.

Why it matters

The Newsletters plugin for WordPress has an authorization bypass vulnerability that allows authenticated attackers to send arbitrary newsletter emails to users of any WordPress role, including administrators. WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent unauthorized mass-mailing and potential phishing.

  • Potential phishing against privileged site users through the site's own outbound email channel
  • Unauthorized mass-mailing of arbitrary newsletter emails to users of any WordPress role

Technical summary

The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to send arbitrary newsletter emails to users of any WordPress role, including administrators, by forging POST fields during a normal post submission.

Defensive priority

Medium priority for WordPress site administrators and security teams to assess exposure and apply patches or mitigations.

Recommended defensive actions

  • Assess exposure by checking if the Newsletters plugin version is 4.17 or earlier
  • Apply patches or updates to the Newsletters plugin to address the authorization bypass vulnerability
  • Monitor for suspicious email activity and potential phishing attempts
  • Restrict access to sensitive areas of the WordPress site
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is due to the plugin not properly verifying that a user is authorized to perform an action. This allows an attacker-supplied role slug via the newsletters_mailinglistsroles POST field to be passed directly to get_users(), enabling unauthorized mass-mailing and potential phishing against privileged site users through the site's own outbound email channel.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75908 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75908

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75908 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75908

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.