VYPR
Unrated severityNVD Advisory· Published Sep 23, 2026

CVE-2026-16264

CVE-2026-16264

Description

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.