VYPR

Email Subscribers \& Newsletters

by WordPress

Source repositories

CVEs (25)

  • CVE-2024-12566MedJan 13, 2025
    risk 0.31cvss 4.8epss 0.00

    The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed…

  • CVE-2024-8254MedOct 2, 2024
    risk 0.28cvss 5.4epss 0.01

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to…

  • CVE-2019-19980MedDec 26, 2019
    risk 0.28cvss 4.3epss 0.01

    The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin…

  • CVE-2024-5703MedJul 17, 2024
    risk 0.21cvss 4.3epss 0.00

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible…

  • CVE-2026-11592MedJul 2, 2026
    risk 0.00cvss 4.3epss 0.00

    The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is…

Page 2 of 2