Veille sécuritéCMS & e-commerce
P4Moyenne
Newsletter for WordPress versions up to and including 9.3.9 exposes a subscriber’s permanent authentication cookie when a signed click-tracking URL is replayed, potentially enabling access to personal data and changes to the subscriber’s profile or subscription. Update to a fixed version when available; rotate the relink key and assess exposure of tracking URLs.
WordPress
IdentifiantCVE-2026-92537
GravitéMoyenne
Exploitationnon connue / non déterminée
CorrectifNon précisé dans les sources
Source : NVD — CVE-2026-92537
Analyse technique
The public click-tracking route can return a subscriber’s raw authentication token when a valid signed tracking URL is requested. The token may permit access to subscriber data and profile or subscription actions.
Impact, versions et correctif
Événement datéNouvelle vulnérabilité publiée par le NVD le 2026-10-01T03:16:59.667Z, dans la période demandée; la fiche a aussi été mise à jour le 2026-10-01T15:17:35.690Z.
ImpactUn attaquant ayant obtenu une URL de suivi signée peut récupérer le jeton permanent d’un abonné, accéder à ses données personnelles, modifier son profil ou le désabonner.
Versions affectéesNewsletter – Send awesome emails from WordPress, versions up to and including 9.3.9
ContournementRotate the relink key to invalidate existing signed tracking URLs; no further workaround is specified in the supplied source.
Exploitation activenon connue / non déterminée
PoC publicinconnu
CVSS5.3
Publication2026-10-01T03:16:59.667Z
Mise à jour2026-10-01T15:17:35.690Z
Action recommandée
Mettre à jour le plugin dès qu’un correctif est disponible et renouveler la clé relink afin d’invalider les URL signées existantes.
Sources
Priorisation DFS : P4 · 1 source(s).