Executive brief
Email Subscribers & Newsletters is a WordPress plugin that manages email subscriptions and newsletters. An unauthenticated attacker can force-unsubscribe or force-confirm any subscriber by knowing their email address, because the plugin fails to verify authorization tokens. This allows attackers to disrupt legitimate subscriptions or add unauthorized confirmations without the subscriber's knowledge or consent.
Technical details
The plugin lacks proper token verification for the subscription status change endpoint before version 5.9.35, allowing unauthenticated access to alter subscriber status. An attacker can change any subscriber's confirmation state (subscribe/unsubscribe) by providing only the email address, exploiting missing access controls (CWE-862). The vulnerability requires knowledge of a valid subscriber email but no authentication, and is easily exploitable via HTTP request to the vulnerable endpoint.
Affected products
- Icegram Email Subscribers & Newsletters before 5.9.35
Timeline
- 2026-09-21: disclosed
- 2026-09-23: patched: Version 5.9.35 released