CubeCart Newsletter Unsubscription Vulnerability Allowing Unauthorized User Removal

Vulnerability

A logic flaw has been identified in CubeCart versions prior to 6.5.11, specifically within the newsletter subscription endpoint. This vulnerability allows an attacker to unsubscribe any user without their consent. By manipulating the 'force_unsubscribe' parameter in the POST request, an attacker can forcibly remove a valid subscriber's email address. The issue has been patched in version 6.5.11.

Impact

Exploitation of this vulnerability allows for unauthorized unsubscription of users from newsletters, potentially leading to missed communications and violation of consent regulations.

Reproduction

To reproduce this vulnerability, subscribe to the newsletter with a valid email address. Then, intercept the POST request to the newsletter subscription endpoint. Change the 'force_unsubscribe' parameter from 0 to 1 and resend the request. The targeted email address will be unsubscribed without confirmation.

Remediation

Users can update to CubeCart version 6.5.11 or later to address this vulnerability.

Added: Sep 22, 2025, 5:21 PM
Updated: Sep 23, 2025, 12:18 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
9.7
remediation
7.7
relevance
0.6
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.