Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF
Summary
| CVE | CVE-2026-17522 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-29 06:17:12 UTC |
| Updated | 2026-08-29 06:17:12 UTC |
| Description | The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters WordPress plugin before 4.17 settings, including the credential protecting its API, via a Cross-Site Request Forgery attack. |
Risk And Classification
Problem Types: CWE-352 Cross-Site Request Forgery (CSRF)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Newsletters | affected 4.17 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/ebb8d4b7-14b5-49ed-b727-129123d6ce45 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Erwan LR (WPScan) (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.