HIGH

CVE-2026-16267

2026-08-08 CVSS v3.1
CVSS
8.1

Description

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

0.27%
Probability of exploitation in next 30 days
19.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE