What is CVE-2026-16267?
The Newsletters WordPress plugin before version 4.16 is vulnerable to PHP Object Injection. Due to a lack of class restrictions when unserializing data from public form submissions, unauthenticated attackers can inject arbitrary PHP objects, potentially leading to remote code execution. Users should update the plugin to the latest version immediately.
Azərbaycanca: Newsletters WordPress plaginində 4.16 versiyasından əvvəl PHP obyekt inyeksiyası zəifliyi mövcuddur. 'unserialize' əməliyyatı zamanı siniflərin məhdudlaşdırılmaması autentifikasiya olunmamış hücumçulara ixtiyari PHP obyektləri yeridərək kod icrasına səbəb ola bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which versions of the Newsletters plugin are affected by CVE-2026-16267?
All versions of the Newsletters WordPress plugin before version 4.16 are affected by this vulnerability.
Does an attacker exploiting CVE-2026-16267 require authentication?
No, unauthenticated attackers can exploit this vulnerability through public form submissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.