Unrated severityNVD Advisory· Published Sep 23, 2026
CVE-2026-16264
CVE-2026-16264
Description
The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.