Executive brief
The Newsletters plugin for WordPress, which manages email marketing and subscriber lists, contains a critical security flaw. An unauthenticated attacker can use a public subscription form to submit malicious data that, when processed by the server, allows them to create unauthorized files or execute arbitrary code. This could lead to a full takeover of the website, theft of subscriber data, or a complete service outage.
Technical details
The Newsletters plugin fails to properly validate or sanitize untrusted input stored through public subscription forms, leading to a PHP Object Injection vulnerability. An unauthenticated attacker can submit a serialized PHP object via a custom text field in the opt-in form. When the attacker later views a newsletter online using their subscriber ID and authkey, the plugin deserializes the stored field value. By utilizing a POP (Property-Oriented Programming) gadget chain present in the bundled GuzzleHttp library, an attacker can trigger a file-write primitive to create a web shell and achieve remote code execution. This issue is fixed in version 4.15.
Affected products
- Tribulant Newsletters (newsletters-lite) < 4.15
Timeline
- 2026-06-23: disclosed: Publicly published by WPScan
- 2026-07-14: advisory: NVD publication date
- 2026-07-14: patched: Fixed in version 4.15