Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 14 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
cvssV3_1
|
Tue, 14 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server. | |
| Title | Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-14T12:28:44.066Z
Reserved: 2026-06-18T07:06:08.362Z
Link: CVE-2026-12583
Updated: 2026-07-14T12:28:32.839Z
Status : Deferred
Published: 2026-07-14T06:17:05.900
Modified: 2026-07-14T16:42:11.910
Link: CVE-2026-12583
No data.
OpenCVE Enrichment
Updated: 2026-07-31T11:00:06Z