Junglewise Threat Intelligence

CVE-2026-83555: Email Subscribers & Newsletters access control bypass in subscription management

CVE-2026-83555 · Severity: medium · CVSS 5.3 · Published 2026-09-23

Technologies: Icegram Email Subscribers & Newsletters. Vendors: Icegram.

Executive brief

Email Subscribers & Newsletters is a WordPress plugin that manages email subscriptions and newsletters. An unauthenticated attacker can force-unsubscribe or force-confirm any subscriber by knowing their email address, because the plugin fails to verify authorization tokens. This allows attackers to disrupt legitimate subscriptions or add unauthorized confirmations without the subscriber's knowledge or consent.

Technical details

The plugin lacks proper token verification for the subscription status change endpoint before version 5.9.35, allowing unauthenticated access to alter subscriber status. An attacker can change any subscriber's confirmation state (subscribe/unsubscribe) by providing only the email address, exploiting missing access controls (CWE-862). The vulnerability requires knowledge of a valid subscriber email but no authentication, and is easily exploitable via HTTP request to the vulnerable endpoint.

Affected products

  • Icegram Email Subscribers & Newsletters before 5.9.35

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Version 5.9.35 released

References

Related threats