Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High1
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-07-14

CVE-2026-12583 - Via A Property Oriented Gadget Chain Bundled With The Newsletters Plugin

The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unauthenticated attackers to inject a PHP object and, via a property-oriented gadget chain bundled with the Newsletters WordPress plugin before 4.15, write arbitrary files and execute code on the server.

PLUGIN Via A Property Oriented Gadget Chain Bundled With The Newsletters

CVE-2026-12583

HIGH CVSS 8.1 2026-07-14
Scroll to top