SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78146

MEDIUM · CVSS 6.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Simple Newsletter Plugin for WordPress versions prior to 4.3.3 is vulnerable to unauthorized data exposure, allowing unauthenticated users to access a subscriber's personal information and the key needed to modify their record. This could lead to privacy breaches and unauthorized changes to subscriber data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-78146
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%
WordPress

Original NVD Description

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.