CVE-2026-1051: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1051 is a Cross-Site Request Forgery (CSRF) vulnerability in the "Newsletter – Send awesome emails from WordPress" plugin for WordPress. It affects all versions up to and including 9.1.0, and was published on January 19–20, 2026, with the CVE record received from Wordfence. The flaw allows unauthenticated attackers to unsubscribe newsletter subscribers by tricking a logged-in user into clicking a malicious link. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is missing or incorrect nonce validation on the hook_newsletter_action() function within the plugin's unsubscription handler (CWE-352: Cross-Site Request Forgery). Because the function does not verify a WordPress nonce before processing unsubscribe actions, an attacker can craft a forged HTTP request that, when triggered by a logged-in user (e.g., via a malicious link), causes the server to process the action as if it were legitimate. The vulnerable code path is visible in the plugin source at unsubscription/unsubscription.php#L141 in the 9.1.0 tag. No authentication is required on the attacker's side; only user interaction from a logged-in WordPress user is needed (Wordfence, WordPress Plugin Trac).

Impact

Successful exploitation allows an unauthenticated attacker to manipulate the newsletter subscriber list by unsubscribing legitimate subscribers without authorization, resulting in a low integrity impact with no confidentiality or availability consequences. While the direct impact is limited to subscriber list manipulation, repeated abuse could disrupt email marketing operations and erode subscriber trust. There is no evidence of lateral movement potential or sensitive data exposure associated with this vulnerability (Wordfence).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1051. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering to trick a logged-in WordPress user into clicking a crafted link, which raises the practical bar for abuse (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Newsletter plugin at version 9.1.0 or earlier, using tools like WPScan or by inspecting publicly visible plugin metadata.
  2. Craft forged request: Construct a malicious URL or HTML page containing a forged HTTP GET or POST request targeting the vulnerable hook_newsletter_action() endpoint with an unsubscribe action and a target subscriber's email or token as a parameter.
  3. Deliver payload: Send the crafted link to a logged-in WordPress user (e.g., a site administrator or editor) via phishing email, social media message, or embedded in a comment/forum post.
  4. Trigger unsubscription: When the logged-in user clicks the link, their browser automatically sends the forged request with their session credentials, causing the server to process the unsubscribe action without nonce verification.
  5. Result: The targeted newsletter subscriber is removed from the mailing list without their consent or the site owner's knowledge (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Logs: WordPress access logs showing unexpected POST or GET requests to the newsletter unsubscription endpoint (e.g., paths associated with hook_newsletter_action) from unusual referrers or external domains.
  • Application Logs: Sudden spikes in unsubscribe events in the Newsletter plugin's activity log, particularly from users who did not initiate the action themselves.
  • Network: Requests to the unsubscription endpoint originating from IP addresses or referrer URLs inconsistent with normal user behavior or known subscriber locations.

Mitigation and workarounds

Users should update the Newsletter plugin to version 9.1.1 or later, which addresses the missing nonce validation in the hook_newsletter_action() function. Until patching is possible, site administrators can restrict access to newsletter management actions or temporarily disable the unsubscription feature. No additional configuration-based workarounds have been publicly documented (Wordfence, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management