Beveiligingsadvies

CVE-2026-17520

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-29 06:00:19
Laatst bijgewerkt 2026-08-30 00:56:53
Toegewezen door WPScan
CVSS-score 4.8
Status PUBLISHED

Beschrijving

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.