CVE-2026-16267

CVE-2026-16267: Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field

Vendor Unknown
Product Newsletters
Published August 8, 2026
Last update August 11, 2026

CVSS base score

What the vulnerability does

01Description

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, allowing unauthenticated attackers to inject arbitrary PHP objects.

Key dates

02Disclosure timeline

August 8, 2026 CVE published
August 11, 2026 Record updated