CVE-2026-17522

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters WordPress plugin before 4.17 settings, including the credential protecting its API, via a Cross-Site Request Forgery attack.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 06:17

Updated : 2026-08-31 20:14


NVD link : CVE-2026-17522

Mitre link : CVE-2026-17522

CVE.ORG link : CVE-2026-17522


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)