PatchSiren cyber security CVE debrief
CVE-2026-75908 contrid CVE debrief
The Newsletters plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 4.17. This allows authenticated attackers with author-level access and above to send arbitrary newsletter emails to users of any WordPress role, including administrators, by forging POST fields during a normal post submission. The vulnerability enables unauthorized mass-mailing and potential phishing against privileged site users through the site's own outbound email channel, highlighting the need for immediate patching or mitigation.
- Vendor
- contrid
- Product
- Newsletters
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-25
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-08-25
- Advisory updated
- 2026-09-28
Who should care
WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent unauthorized mass-mailing and potential phishing against privileged site users.
Why it matters
The Newsletters plugin for WordPress has an authorization bypass vulnerability that allows authenticated attackers to send arbitrary newsletter emails to users of any WordPress role, including administrators. WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent unauthorized mass-mailing and potential phishing.
- Potential phishing against privileged site users through the site's own outbound email channel
- Unauthorized mass-mailing of arbitrary newsletter emails to users of any WordPress role
Technical summary
The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to send arbitrary newsletter emails to users of any WordPress role, including administrators, by forging POST fields during a normal post submission.
Defensive priority
Medium priority for WordPress site administrators and security teams to assess exposure and apply patches or mitigations.
Recommended defensive actions
- Assess exposure by checking if the Newsletters plugin version is 4.17 or earlier
- Apply patches or updates to the Newsletters plugin to address the authorization bypass vulnerability
- Monitor for suspicious email activity and potential phishing attempts
- Restrict access to sensitive areas of the WordPress site
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is due to the plugin not properly verifying that a user is authorized to perform an action. This allows an attacker-supplied role slug via the newsletters_mailinglistsroles POST field to be passed directly to get_users(), enabling unauthorized mass-mailing and potential phishing against privileged site users through the site's own outbound email channel.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75908 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75908
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75908 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75908
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.17/includes/checkinit.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/newsletters-lite/tags/4.17/wp-mailinglist.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.