CVE-2026-17520CWE-326

CVE-2026-17520

Medium · published August 29, 2026

CVSS v3.1
4.8
EPSS
0%
Percentile
2.1
In the wild
Unconfirmed
What it is

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers and sending emails, when the optional API has been enabled.

The record
Technical detail
CVSS v3.1
4.8 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00121 · 2.1th percentile
Weakness
CWE-326 · Inadequate Encryption Strength
Published
2026-08-29T10:17Z
References (1)
EPSS history
Timeline
  • 30 AUG 16:16Z
    EPSS moved — → 0%
    epss
  • 29 AUG 06:00Z
    Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key
    cvelistv5