Junglewise Threat Intelligence

CVE-2026-57645: Tribulant Software Newsletters broken access control in newsletters_subscribers

CVE-2026-57645 · Severity: high · CVSS 8.1 · Published 2026-06-26

Executive brief

The Newsletters plugin for WordPress, used for managing email marketing and subscriber lists, contains a security flaw that fails to properly verify user permissions. This could allow an unauthorized person to perform administrative actions if they can trick a site administrator into clicking a malicious link or visiting a specific page. Such an attack could lead to unauthorized changes to the newsletter system or disruption of subscriber services.

Technical details

A broken access control vulnerability exists in the Tribulant Software Newsletters plugin (newsletters-lite) for WordPress in versions up to and including 4.13. The flaw is rooted in missing authorization checks (CWE-862) within the newsletters_subscribers component. Although the vulnerability is associated with the 'newsletters_subscribers' role, the CVSS vector indicates it can be triggered by an unauthenticated remote attacker via user interaction (UI:R), likely through Cross-Site Request Forgery (CSRF) or a similar vector that leverages a privileged user's session. Successful exploitation allows an attacker to perform actions they are not authorized to execute, potentially impacting the integrity and availability of the plugin's data. The issue is resolved in version 4.14.

Affected products

  • Tribulant Software Newsletters (newsletters-lite) <= 4.13

Timeline

  • 2026-03-21: other: Reported by Prodigysec
  • 2026-06-26: advisory: Published by Patchstack
  • 2026-06-26: disclosed: NVD publication date

References