CVE-2026-16267

Published: Ago 08, 2026 Last Modified: Ago 08, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0016
Percentile
0,1th
Updated

EPSS Score Trend (Last 3 Days)

https://wpscan.com/vulnerability/b51c11d6-5bfa-4b2c-b348-cda19889deee/