Executive brief
The Newsletters plugin for WordPress, used for managing email marketing and subscriber lists, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could exploit this to bypass security checks and potentially access or modify data without needing to log in. This could lead to unauthorized changes to newsletter settings or exposure of subscriber information.
Technical details
The Newsletters (newsletters-lite) plugin for WordPress suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This allows an unauthenticated remote attacker to execute functions or access data that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. The issue is resolved in version 4.14.
Affected products
- Tribulant Software Newsletters (newsletters-lite) <= 4.13
Timeline
- 2026-04-30: disclosed: Reported by HieuPenguinnn
- 2026-06-18: advisory: Patchstack advisory published
- 2026-06-26: patched: NVD publication and patch availability confirmed in version 4.14