MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #9

WordPress Newsletter plugin leaks subscriber login cookies via tracking links

Original: The WordPress Newsletter plugin leaks a subscriber's login cookie to anyone holding a tracking link from a sent email, e

The Newsletter plugin for WordPress has a vulnerability in versions 9.3.9 and earlier: anyone holding a tracking link from a sent email can obtain a subscriber's login cookie, exposing stored personal data. The flaw is tracked as CVE-2026-92537. The developer has released version 9.4.0, and site administrators are being urged to update immediately.

Why now: Site administrators and security researchers are spreading the warning so affected WordPress sites can patch quickly.

WordPressNewsletter pluginCVE-2026-92537

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/563844