← WordPress Vulnerabilities
WordPress security by component

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce collects email subscribers and provides tools for newsletters, automated messages, email lists, and campaign management in WordPress.

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce (email-subscribers) is a WordPress plugin with 22 published CVE records in this archive. The latest tracked vulnerability was published Sep 07, 2026; the highest published CVSS base score is 9.8.

Plugin slug: email-subscribers

CVE-2026-12757: Email Subscribers permits unauthenticated shortcode execution

Email Subscribers through 5.9.27 passes an attacker-controlled value to do_shortcode without adequate validation. An unauthenticated attacker can execute any shortcode registered on the site, with the resulting data exposure or state change determined by the available shortcodes.

PublishedSep 07, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for email-subscribers
Safe version
Sep 07, 2026 CVE-2026-12757
Email Subscribers permits unauthenticated shortcode execution
Email Subscribers through 5.9.27 passes an attacker-controlled value to do_shortcode without adequate validation. An unauthenticated attacker can execute any shortcode registered on the site, with the resulting data exposure or state change determined by the available shortcodes.
See mitigation notes
CVE6.5
NVDPending
Aug 31, 2026 CVE-2026-81290
Email Subscribers & Newsletters permits unauthenticated XSS
Email Subscribers & Newsletters through 5.9.33 allows an unauthenticated attacker to inject script into affected output. The script executes when a victim interacts with that output and can act within the victim's browser session.
5.9.34
CVE7.1
NVDPending
Jul 02, 2026 CVE-2026-11592
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress: A security weakness
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.9.27.
See mitigation notes
CVE4.3
NVDPending
Mar 04, 2026 CVE-2026-1651
Email Subscribers by Icegram Express: SQL injection
Email Subscribers by Icegram Express is affected by SQL injection. Exploitation requires an authenticated administrator account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE6.5
NVDPending
Dec 12, 2025 CVE-2025-12348
Icegram Express - Email Subscribers, Newsletters and Marketing Automation: A security weakness
Icegram Express - Email Subscribers, Newsletters and Marketing Automation is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 21, 2025 CVE-2025-66055
Email Subscribers & Newsletters: Code execution
Email Subscribers & Newsletters is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Nov 19, 2025 CVE-2025-12349
Icegram Express - Email Subscribers, Newsletters and Marketing Automation: Denial of service
Icegram Express - Email Subscribers, Newsletters and Marketing Automation is affected by denial of service. The vulnerable path is reachable without authentication. A successful request can exhaust or disrupt the affected operation and make site functionality unavailable.
See mitigation notes
CVE5.3
NVDPending
Oct 02, 2024 CVE-2024-8254
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce: A security weakness
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD6.3
Sep 26, 2024 CVE-2024-8771
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce: A security weakness
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 17, 2024 CVE-2024-5703
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce: A security weakness
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 02, 2024 CVE-2024-6172
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce: SQL injection
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Jun 26, 2024 CVE-2024-37252
Email Subscribers & Newsletters: SQL injection
Email Subscribers & Newsletters is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVDPending
Jun 21, 2024 CVE-2024-5756
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce: SQL injection
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVDPending
Jun 09, 2024 CVE-2024-31352
Email Subscribers & Newsletters: A security weakness
Email Subscribers & Newsletters is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
May 23, 2024 CVE-2024-3626
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce: A security weakness
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 27, 2024 CVE-2024-22300
Email Subscribers & Newsletters: Cross-site scripting
Email Subscribers & Newsletters is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Nov 07, 2023 CVE-2022-45810
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce: A security weakness
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.7
NVD9.8
Oct 20, 2023 CVE-2023-5414
Icegram Express: Filesystem traversal
Icegram Express is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.1
NVD7.2
Jul 28, 2019 CVE-2019-14364
Email Subscribers: Cross-site scripting
Email Subscribers is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jul 19, 2019 CVE-2019-13569
Email Subscribers: SQL injection
Email Subscribers is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD9.8
Jun 26, 2018 CVE-2018-0602
Email Subscribers: Cross-site scripting
Email Subscribers is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jan 26, 2018 CVE-2018-6015
Email Subscribers: A security weakness
Email Subscribers is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5