Loading market data...
← Back to CVE feed

CVE-2026-78146

MEDIUM CVSS 6.5 View on NVD ↗

Description

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Published: Aug 26, 2026 06:16 UTC Modified: Aug 26, 2026 16:30 UTC