CVE-2026-16267
Description
AI Translation Available
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0016
Percentile
0,1th
Updated
EPSS Score Trend (Last 3 Days)
https://wpscan.com/vulnerability/b51c11d6-5bfa-4b2c-b348-cda19889deee/