CVE-2026-16268: Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16268?
CVE-2026-16268 is rated with a risk score of 64, indicating a moderate severity level.
How do I fix CVE-2026-16268?
To fix CVE-2026-16268, update the Newsletters WordPress plugin to version 4.16 or later.
What type of vulnerability is CVE-2026-16268?
CVE-2026-16268 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by CVE-2026-16268?
Anyone using the Newsletters WordPress plugin version prior to 4.16 is affected by CVE-2026-16268.
Can CVE-2026-16268 lead to data exposure?
Yes, CVE-2026-16268 can potentially lead to data exposure by allowing attackers to make requests to sensitive internal resources.