
🚨 WordPress Newsletters plugin hit by object injection flaw CVE-2026-16267 affects Newsletters versions before 4.16. Unauthenticated attackers can inject arbitrary PHP objects because data received through a public form is unserialized without restricting allowed classes. 🔎 Source: WPScan / CVE. #WordPress #PHP #CVE #WebSecurity #CyberSecurity
Post summary
The post announces CVE-2026-16267, an object injection flaw in WordPress Newsletters before 4.16 that allows unauthenticated PHP object injection via a public form.
