CVE-2026-16264 UNKNOWN

CVE-2026-16264

Published: 2026-09-23

Description

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subscriber's personal data and overwrite any subscriber's record including their email address.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…