Beveiligingsadvies

CVE-2026-78146

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-26 06:00:22
Laatst bijgewerkt 2026-08-26 14:43:06
Toegewezen door WPScan
CVSS-score 6.5
Status PUBLISHED

Beschrijving

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that subscriber's stored details, allowing unauthenticated users to disclose a subscriber's personal data along with the key that authorises changes to their record.