---
cve: "CVE-2026-92537"
severity: "MEDIUM"
cvss: 5.3
epss: ""
vendor: "satollo"
kev: false
exploited: false
published: "2026-10-01 03:16:59"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-04T04:50:33+02:00"
---

# CVE-2026-92537

> 5.3 MEDIUM

## Beschreibung

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 The plugin's public click-tracking REST route `/tnp/l/` is registered with `permission_callback => '__return_true'` and, upon receiving a valid keyed-MD5 signature, calls `set_user_cookie()`, which emits a `Set-Cookie: newsletter=-` response header to the requester because the subscriber object loaded via `get_user()` lacks the `_trusted` property, causing `get_user_key()` to return the raw token column value instead of its MD5-masked variant. This makes it possible for unauthenticated attackers who obtain any signed click-tracking URL for a target subscriber to receive that subscriber's permanent raw authentication cookie, which they can then use to export the subscriber's full PII record via the JSON profile-export endpoint (`?na=px`), rewrite the subscriber's stored profile (`?na=ps`), and silently unsubscribe the subscriber via the RFC-8058 one-click endpoint (`?na=ocu`), none of which require a nonce, password, or email challenge. Signed tracking URLs are embedded in every external link of every newsletter delivered to a subscriber, carry no timestamp, and never expire until the site's relink key rotates, meaning that any party who observes such a URL — through a forwarded email, a shared inbox, a mail-gateway log, or Referer headers on the redirect target, which has no Referrer-Policy set — can replay it indefinitely to obtain the victim's credential.

## CNA-Record (Kanon, cvelistV5)

- CNA: **Wordfence**
- State: PUBLISHED
- Stand: 2026-10-01 14:21:14
- CNA-CVSS: **5.3** (`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Keine | good |

## Referenzen

- <https://www.wordfence.com/threat-intel/vulnerabilities/id/ed68a4ff-a2aa-4df7-96b1-f094bce4b9b7?source=cve>
- <https://plugins.trac.wordpress.org/browser/newsletter/tags/9.3.9/statistics/statistics.php#L174>
- <https://plugins.trac.wordpress.org/browser/newsletter/tags/9.3.9/includes/module.php#L403>
- <https://plugins.trac.wordpress.org/browser/newsletter/tags/9.3.9/includes/module-base.php#L441>
- <https://plugins.trac.wordpress.org/browser/newsletter/tags/9.3.9/statistics/statistics.php#L107>
- <https://plugins.trac.wordpress.org/browser/newsletter/tags/9.3.9/statistics/statistics.php#L335>
- <https://plugins.trac.wordpress.org/browser/newsletter/tags/9.3.9/includes/module-base.php#L1209>
- <https://plugins.trac.wordpress.org/changeset?reponame=&new=3709894%40newsletter%2Ftags%2F9.4.0&old=3695457%40newsletter%2Ftags%2F9.3.9>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-92537) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
