HIGH
CVE-2026-16267
CVSS
8.1
Description
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
0.27%
Probability of exploitation in next 30 days
19.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.