Vulnerability Description
The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.
References
FAQ
What is CVE-2026-16269?
CVE-2026-16269 is a documented vulnerability. The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform pri...
How severe is CVE-2026-16269?
CVSS scoring is not yet available for CVE-2026-16269. Check NVD for updates.
Is there a patch for CVE-2026-16269?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.