---
id: CVE-2026-16269
title: >-
  The Newsletters WordPress plugin before 4.16 does not strictly compare its API
  authentication key, allowing unauthenticated attackers to bypass the API
  authentication via type juggling and perform privileged actions such as
  modifying sub…
summary: >-
  The Newsletters WordPress plugin before 4.16 does not strictly compare its API
  authentication key, allowing unauthenticated attackers to bypass the API
  authentication via type juggling and perform privileged actions such as
  modifying sub…
severity: none
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16269'
references:
  - url: 'https://wpscan.com/vulnerability/8b09afba-16a5-4d6c-9e85-84433a3c0d66/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00363
epssPercentile: 0.27462
ingestedAt: '2026-08-09T03:32:40.206Z'
---

## Overview

The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthenticated attackers to bypass the API authentication via type juggling and perform privileged actions such as modifying subscriber records and sending emails, when the optional API has been enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
