Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #9
WordPress Newsletter plugin leaks subscriber login cookies via tracking links
Original: The WordPress Newsletter plugin leaks a subscriber's login cookie to anyone holding a tracking link from a sent email, e
The Newsletter plugin for WordPress has a vulnerability in versions 9.3.9 and earlier: anyone holding a tracking link from a sent email can obtain a subscriber's login cookie, exposing stored personal data. The flaw is tracked as CVE-2026-92537. The developer has released version 9.4.0, and site administrators are being urged to update immediately.
Why now: Site administrators and security researchers are spreading the warning so affected WordPress sites can patch quickly.
WordPressNewsletter pluginCVE-2026-92537
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/563844