Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
Description
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the content of private, password protected, pending, and draft posts and pages.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The Email Subscribers by Icegram Express plugin for WordPress, up to version 5.7.34, lacks a capability check on the preview_email_template_design function, allowing Subscriber-level and above users to access private posts and pages.
Vulnerability
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 5.7.34. The root cause is a missing capability check on the preview_email_template_design function, which fails to enforce proper authorization before processing requests. This allows authenticated attackers to retrieve sensitive content from private, password-protected, pending, and draft posts and pages.
Exploitation
To exploit this vulnerability, an attacker must have a valid WordPress account with at least Subscriber-level access. No additional privileges or special conditions are required. The attacker can send a crafted request to the vulnerable preview_email_template_design function, which will return the content of restricted posts and pages without proper permission validation.
Impact
Successful exploitation enables an attacker to extract the full content of private, password-protected, pending, and draft posts and pages. This leads to information disclosure of potentially sensitive data, including unpublished content, draft revisions, or password-protected material. The attacker does not need to be logged in as an administrator or editor; any authenticated user with Subscriber-level or higher access can perform this attack.
Mitigation
The vendor has released version 5.9.24 of the plugin (last updated 2026-05-13), which includes a fix for this vulnerability. Users should update to version 5.9.24 or later immediately [1]. There are no known workarounds for unpatched versions; applying the update is the only mitigation. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <=5.7.34
Patches
1r3157336Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.