CyberRota Analysis
AI-GeneratedThe Newsletters plugin for WordPress versions prior to 4.16 is vulnerable due to improper API authentication key comparison, enabling unauthenticated attackers to exploit type juggling. This flaw allows them to perform privileged actions, including modifying subscriber records and sending emails, if the optional API feature is enabled. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential unauthorized access and data manipulation risks.
Original NVD Description
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.