CVE-2026-17520 - CERT CVE
ID CVE-2026-17520
Sažetak The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.
Reference
CVSS
Base: 4.8
Impact: 2.5
Exploitability:2.2
Pristup
VektorSloženostAutentikacija
NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW LOW
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Zadnje važnije ažuriranje 31-08-2026 - 20:14
Objavljeno 29-08-2026 - 06:17