haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-162694.8medium[patched]

Unauthenticated API Authentication Bypass via Type Juggling

TARGET ECOSYSTEM / VENDORTribulant
AFFECTED PRODUCTNewsletters (< 4.16)
CWE CLASSIFICATIONCWE-287: Improper Authentication
PUBLISHED DATE2026-08-03

Summary

Newsletters (< 4.16) does not strictly compare its API authentication key. This allows unauthenticated attackers to bypass the API authentication via a PHP type juggling vulnerability and perform privileged actions (such as modifying subscriber records and dispatching emails) when the optional API has been enabled.

Vulnerability Analysis

The plugin’s API authentication mechanism at wp-mailinglist-api.php:59 relies on a loose comparison (==) when verifying the provided API key against the stored key. By sending the JSON boolean true ("api_key": true), an attacker triggers PHP type juggling where true == any_non_empty_string evaluates to true, completely bypassing the authentication check.

Fixed In

Fixed in version 4.16 by enforcing strict type checking (is_string) and time-safe string comparison via hash_equals().