August 29, 2026

Patching One Instance Does Not Fix the Class: PHP Object Injection to RCE in the Newsletters Plugin…

How a prior CVE fix covered one unserialize() call and missed two others in the same function, leaving unauthenticated remote code…

By Yaswanth R. Sunkara

5 min read