The Newsletters WordPress plugin before version 4.17 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This vulnerability allows attackers to make logged-in administrators overwrite arbitrary plugin settings. The CVE record was published on 2026-08-29T06:17:12.290Z and has not been modified since then. Affected administrators should be aware of this vulnerability and take steps to patch or mitig [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T07:17:09.790Z and has not been modified since then. The Newsletters WordPress plugin before version 4.16 has a vulnerability allowing unauthenticated attackers to bypass API authentication via type juggling when the optional API is enabled. This issue may impact organizations using the plugin, es [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-08T07:17:09.667Z and has not been modified since then. The Newsletters WordPress plugin before 4.16 does not restrict classes when unserialising public form submissions, allowing unauthenticated attackers to inject arbitrary PHP objects with potential impact on confidentiality, integrity, and availa [truncated]