CVE-2026-16268: Unknown Newsletters
High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.
Affected products
- Unknown Newsletters: before 4.16 (fixed in 4.16)
Published 2026-08-06. Last modified 2026-08-26.