Junglewise Threat Intelligence

CVE-2026-12583: Tribulant Newsletters PHP object injection in subscriber custom fields

CVE-2026-12583 · Severity: info · CVSS 8.1 · Published 2026-07-14

Technologies: Tribulant Newsletters. Vendors: Tribulant.

Executive brief

The Newsletters plugin for WordPress, which manages email marketing and subscriber lists, contains a critical security flaw. An unauthenticated attacker can use a public subscription form to submit malicious data that, when processed by the server, allows them to create unauthorized files or execute arbitrary code. This could lead to a full takeover of the website, theft of subscriber data, or a complete service outage.

Technical details

The Newsletters plugin fails to properly validate or sanitize untrusted input stored through public subscription forms, leading to a PHP Object Injection vulnerability. An unauthenticated attacker can submit a serialized PHP object via a custom text field in the opt-in form. When the attacker later views a newsletter online using their subscriber ID and authkey, the plugin deserializes the stored field value. By utilizing a POP (Property-Oriented Programming) gadget chain present in the bundled GuzzleHttp library, an attacker can trigger a file-write primitive to create a web shell and achieve remote code execution. This issue is fixed in version 4.15.

Affected products

  • Tribulant Newsletters (newsletters-lite) < 4.15

Timeline

  • 2026-06-23: disclosed: Publicly published by WPScan
  • 2026-07-14: advisory: NVD publication date
  • 2026-07-14: patched: Fixed in version 4.15

References

Related threats