CVE-2026-83555: CWE-862 Missing Authorization in Email Subscribers & Newsletters
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
AI Analysis
Technical Summary
CVE-2026-83555 is a missing authorization vulnerability (CWE-862) in the Email Subscribers & Newsletters WordPress plugin versions prior to 5.9.35. The plugin fails to verify the per-subscriber management token before allowing changes to subscription status. This allows unauthenticated attackers to manipulate subscription states of arbitrary subscribers if they know the subscriber's email address.
Potential Impact
An attacker can forcibly unsubscribe or confirm any subscriber's subscription status without authentication, potentially disrupting subscriber lists or causing unwanted subscription changes. There is no indication of further impact such as data disclosure or code execution.
Mitigation Recommendations
Upgrade the Email Subscribers & Newsletters plugin to version 5.9.35 or later where this authorization check has been implemented. No other mitigation guidance is provided.
CVE-2026-83555: CWE-862 Missing Authorization in Email Subscribers & Newsletters
Description
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
CVSS v3.1
Score 5.3medium
Affected software
Email Subscribers & Newsletters
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-83555 is a missing authorization vulnerability (CWE-862) in the Email Subscribers & Newsletters WordPress plugin versions prior to 5.9.35. The plugin fails to verify the per-subscriber management token before allowing changes to subscription status. This allows unauthenticated attackers to manipulate subscription states of arbitrary subscribers if they know the subscriber's email address.
Potential Impact
An attacker can forcibly unsubscribe or confirm any subscriber's subscription status without authentication, potentially disrupting subscriber lists or causing unwanted subscription changes. There is no indication of further impact such as data disclosure or code execution.
Mitigation Recommendations
Upgrade the Email Subscribers & Newsletters plugin to version 5.9.35 or later where this authorization check has been implemented. No other mitigation guidance is provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-31T18:29:23.814Z
- State
- PUBLISHED
Threat ID: 6ab36d3ff7a7c541065abc9d
Added to database: 09/23/2026, 06:10:07 UTC
Last enriched: 09/23/2026, 06:33:13 UTC
Last updated: 09/24/2026, 01:57:05 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.