CyberRota Analysis
AI-GeneratedThe Newsletters plugin for WordPress versions prior to 4.16 is vulnerable due to insufficient restrictions on classes during the unserialization of user-submitted data, enabling unauthenticated attackers to inject arbitrary PHP objects. This could lead to remote code execution or other malicious activities on affected sites. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.
Original NVD Description
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.