CVE-2026-12583

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.
Configurations

No configuration.

History

14 Jul 2026, 13:18

Type Values Removed Values Added
CWE CWE-502
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

14 Jul 2026, 06:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 06:17

Updated : 2026-07-14 16:42


NVD link : CVE-2026-12583

Mitre link : CVE-2026-12583

CVE.ORG link : CVE-2026-12583


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data