{"apiVersion":"1.0","identifier":"CVE-2026-75908","description":"The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to send arbitrary newsletter emails to users of any WordPress role, including administrators, by forging POST fields during a normal post submission. This allows an attacker-supplied role slug via the newsletters_mailinglistsroles POST field to be passed directly to get_users(), enabling unauthorized mass-mailing and potential phishing against privileged site users through the site-s own outbound email channel.","publishedAt":"2026-08-25T12:16:24","lastModifiedAt":"2026-08-26T16:19:05","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75908","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","epssProbability":0.00222,"riskScore":0.44,"affectedProduct":"Newsletters","affectedVersions":"<=4.17","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-75908","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-75908","en":"https://www.redsauce.net/en/cves/CVE-2026-75908","fr":"https://www.redsauce.net/fr/cves/CVE-2026-75908","pt":"https://www.redsauce.net/pt/cves/CVE-2026-75908","de":"https://www.redsauce.net/de/cves/CVE-2026-75908","sk":"https://www.redsauce.net/sk/cves/CVE-2026-75908","el":"https://www.redsauce.net/el/cves/CVE-2026-75908"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-75908"}}