
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1051 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Newsletter – Send awesome emails from WordPress" plugin for WordPress. It affects all versions up to and including 9.1.0, and was published on January 19–20, 2026, with the CVE record received from Wordfence. The flaw allows unauthenticated attackers to unsubscribe newsletter subscribers by tricking a logged-in user into clicking a malicious link. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is missing or incorrect nonce validation on the hook_newsletter_action() function within the plugin's unsubscription handler (CWE-352: Cross-Site Request Forgery). Because the function does not verify a WordPress nonce before processing unsubscribe actions, an attacker can craft a forged HTTP request that, when triggered by a logged-in user (e.g., via a malicious link), causes the server to process the action as if it were legitimate. The vulnerable code path is visible in the plugin source at unsubscription/unsubscription.php#L141 in the 9.1.0 tag. No authentication is required on the attacker's side; only user interaction from a logged-in WordPress user is needed (Wordfence, WordPress Plugin Trac).
Successful exploitation allows an unauthenticated attacker to manipulate the newsletter subscriber list by unsubscribing legitimate subscribers without authorization, resulting in a low integrity impact with no confidentiality or availability consequences. While the direct impact is limited to subscriber list manipulation, repeated abuse could disrupt email marketing operations and erode subscriber trust. There is no evidence of lateral movement potential or sensitive data exposure associated with this vulnerability (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1051. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to trick a logged-in WordPress user into clicking a crafted link, which raises the practical bar for abuse (Wordfence, Red Hat CVE).
hook_newsletter_action() endpoint with an unsubscribe action and a target subscriber's email or token as a parameter.hook_newsletter_action) from unusual referrers or external domains.Users should update the Newsletter plugin to version 9.1.1 or later, which addresses the missing nonce validation in the hook_newsletter_action() function. Until patching is possible, site administrators can restrict access to newsletter management actions or temporarily disable the unsubscription feature. No additional configuration-based workarounds have been publicly documented (Wordfence, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."