Feed/CVE-2026-16269
CVE-2026-16269MEDIUMCVSS 4.8

CVE-2026-16269

Published Aug 8, 2026·Updated Aug 11, 2026

NVD Description

The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free