Executive brief
The Newsletter WordPress plugin for managing email subscriptions fails to securely generate its email tracking signing key, using predictable values instead of cryptographically random data. An attacker who discovers this weak key can forge tracking links to steal subscriber session tokens and access or modify any subscriber's personal information stored in the database, without needing to authenticate.
Technical details
The vulnerability stems from insufficient entropy in the generation of the email tracking signing key and the use of an unkeyed hash (CWE-326: Inadequate Encryption Strength) to sign tracking links. An unauthenticated attacker can recover the predictable signing key through offline brute-force or analysis, then forge tracking links that impersonate legitimate email tracking calls. By crafting malicious tracking links, an attacker can obtain any subscriber's session token and subsequently read or modify that subscriber's stored personal data. The vulnerability is present in versions before 9.3.8, which addressed the issue. Attack requires network access to send forged tracking links but no prior authentication.
Affected products
- Newsletter Newsletter before 9.3.8
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: fixed in version 9.3.8