AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16268

HIGH · CVSS 8.2 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Newsletters plugin for WordPress versions prior to 4.16 is vulnerable due to a lack of authentication and validation for bounce-processing requests, enabling unauthenticated attackers to send requests to arbitrary URLs on the server. This flaw could lead to unauthorized access or data exfiltration, posing a significant risk to the integrity and security of the affected WordPress sites. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate potential exploits.

CVE
CVE-2026-16268
Severity
HIGH
CVSS
8.2
EPSS
0.19%
WordPress

Original NVD Description

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.