CVE-2026-16264

Status: Received

Description

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.

Published
September 23, 2026 6:17 AM
Last Modified
September 23, 2026 6:17 AM
Source
[email protected]

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.