Junglewise Threat Intelligence

CVE-2026-86823: Newsletter WordPress plugin open redirect in subscription action

CVE-2026-86823 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Executive brief

The Newsletter WordPress plugin is widely used to manage email subscriber lists and handle subscription workflows. Before version 9.3.7, the plugin fails to validate redirect URLs after users subscribe, allowing attackers to redirect subscribers to phishing or malicious sites and steal their subscriber authentication tokens. This enables account takeover of subscriber accounts and could be used in phishing campaigns to compromise user data.

Technical details

This is an unvalidated redirect vulnerability (CWE-601) in the public subscription action flow. The plugin does not properly validate the destination parameter (ncu) used in post-subscription redirects, allowing unauthenticated attackers to craft malicious URLs that redirect users to arbitrary external sites. The vulnerability also discloses a subscriber token that grants authenticated access to subscriber record front-end actions. Attack vector is network-based via specially crafted URLs shared with users; no authentication is required. Exploitation allows credential theft and account takeover. The vendor released a fix in version 9.3.7.

Affected products

  • Newsletter (Tribulant Software) Newsletter before 9.3.7

Timeline

  • 2026-09-14: disclosed
  • 2026-09-16: patched: version 9.3.7 released

References