What is CVE-2026-16268?
CVE-2026-16268 allows unauthenticated attackers to trigger server-side requests to arbitrary internal or external hosts via a bounce-processing request in the Newsletters WordPress plugin before 4.16. This vulnerability exposes sites to SSRF attacks, enabling unauthorized interaction with internal resources and potential data exfiltration.
Azərbaycanca: CVE-2026-16268 boşluğu Newsletters WordPress plaginin 4.16-dan əvvəlki versiyalarında bounce-processing sorğusunu autentifikasiyasız qəbul edərək server tərəfində istifadəçi tərəfindən təqdim olunan URL-i fetch etməyə imkan verir. Təhlükəsizlik yaması tətbiq olunmayan saytlar Server-Side Request Forgery (SSRF) hücumlarına məruz qala bilər.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which WordPress plugin is affected by CVE-2026-16268 and what is the main risk?
This vulnerability affects the Newsletters plugin before version 4.16. The main risk is that unauthenticated attackers can perform Server-Side Request Forgery (SSRF) attacks by triggering server-side requests to arbitrary URLs.
Is authentication required to exploit CVE-2026-16268?
No, this vulnerability can be exploited without authentication. An attacker can use a bounce-processing request to make the server fetch a user-supplied URL, enabling interaction with internal or external hosts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.