CVE-2026-16267: Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Newsletters pluginto a version that resolves this vulnerability.Fixed in 4.16
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16267?
CVE-2026-16267 has a risk rating of 71, indicating a significant security concern.
How do I fix CVE-2026-16267?
To fix CVE-2026-16267, update the Newsletters WordPress plugin to version 4.16 or higher.
What type of vulnerability is CVE-2026-16267?
CVE-2026-16267 is an unauthenticated PHP object injection vulnerability.
Who is affected by CVE-2026-16267?
CVE-2026-16267 affects all versions of the Newsletters WordPress plugin before 4.16.
What are the potential impacts of CVE-2026-16267?
Exploitation of CVE-2026-16267 could allow unauthenticated attackers to inject and execute arbitrary PHP objects.