CVE-2026-17520
The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.
- Published Aug 29, 2026
- CVSS 4.8 medium
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available