Loading market data...
← Back to CVE feed

CVE-2026-16269

UNKNOWN View on NVD ↗

Description

The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.

Published: Aug 08, 2026 07:17 UTC Modified: Aug 08, 2026 07:17 UTC