Newsletters

WordPress plugin · newsletters · WordPress.org ↗
0
Critical
3
High
6
Known total
0
Unfixed
Running Newsletters on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.1
Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field
CVE.org
>=0, <4.16 v4.16 CVE-2026-16267 Aug 8, 2026
HIGH
CVSS 8.2
Newsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce Handler
CVE.org
>=0, <4.16 v4.16 CVE-2026-16268 Aug 6, 2026
HIGH
CVSS 8.1
Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field
CVE.org
>=0, <4.15 v4.15 CVE-2026-12583 Jul 14, 2026
MEDIUM
CVSS 4.8
Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key
CVE.org
>=0, <4.17 v4.17 CVE-2026-17520 Aug 29, 2026
MEDIUM
CVSS 5.4
Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF
CVE.org
>=0, <4.17 v4.17 CVE-2026-17522 Aug 29, 2026
MEDIUM
CVSS 4.8
Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling
CVE.org
>=0, <4.16 v4.16 CVE-2026-16269 Aug 8, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.