AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16267

HIGH · CVSS 8.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Newsletters plugin for WordPress versions prior to 4.16 is vulnerable due to insufficient restrictions on classes during the unserialization of user-submitted data, enabling unauthenticated attackers to inject arbitrary PHP objects. This could lead to remote code execution or other malicious activities on affected sites. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-16267
Severity
HIGH
CVSS
8.1
EPSS
0.27%
WordPress

Original NVD Description

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.