Skip to content

Known CVE

Newsletters < 4.16 - Unauthenticated SSRF via SNS Bounce Handler

Newsletters WordPress plugin < 4.16 contains a server-side request forgery caused by lack of authentication and validation in bounce-processing requests, letting unauthenticated attackers make arbitrary requests to internal or external hosts.

CVE-2026-16268

Medium2026CVSS 5.3CWE-918

cve2026 · wordpress · wp-plugin · newsletters-lite · ssrf · unauth · oast

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website