CVE-2025-67911: WordPress Newsletters plugin <= 4.11 - PHP Object Injection vulnerability
Published Jan 8, 2026
·Updated
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.
Affected Software
2 affected components
Tribulant Software Newsletters<=4.11
wordpress/newsletters<=4.11
Event History
Jan 8, 2026
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67911?
CVE-2025-67911 has a medium severity rating due to the potential for object injection vulnerabilities.
2
How do I fix CVE-2025-67911?
To fix CVE-2025-67911, update Tribulant Software Newsletters to version 4.12 or later.
3
What versions are affected by CVE-2025-67911?
CVE-2025-67911 affects all versions of Tribulant Software Newsletters from n/a through version 4.11.
4
What types of attacks can exploit CVE-2025-67911?
CVE-2025-67911 can be exploited through deserialization attacks, leading to object injection.
5
Is CVE-2025-67911 specific to any platform?
Yes, CVE-2025-67911 specifically affects the Newsletters plugin for WordPress.