CVE-2026-16267 - Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
CVE ID :CVE-2026-16267
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 8, 2026, 6 a.m. | 1 hour, 27 minutes ago
Description :The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...