Feed/CVE-2026-16268
CVE-2026-16268

CVE-2026-16268

Published Aug 6, 2026·Updated Aug 6, 2026

NVD Description

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the server side, allowing unauthenticated attackers to make the site issue requests to arbitrary internal or external hosts.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free