CVE-2026-12583
Newsletters
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.
- CVSS
- 8.1
- EPSS
- 0.33% 25.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.14