Unauthenticated API Authentication Bypass via Type Juggling
Summary
Newsletters (< 4.16) does not strictly compare its API authentication key. This allows unauthenticated attackers to bypass the API authentication via a PHP type juggling vulnerability and perform privileged actions (such as modifying subscriber records and dispatching emails) when the optional API has been enabled.
Vulnerability Analysis
The plugin’s API authentication mechanism at wp-mailinglist-api.php:59 relies on a loose comparison (==) when verifying the provided API key against the stored key. By sending the JSON boolean true ("api_key": true), an attacker triggers PHP type juggling where true == any_non_empty_string evaluates to true, completely bypassing the authentication check.
Fixed In
Fixed in version 4.16 by enforcing strict type checking (is_string) and time-safe string comparison via hash_equals().