Missing Authorization Vulnerability in Icegram Express Plugin for WordPress
CVE-2025-12348
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 December 2025
What is CVE-2025-12348?
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress has a vulnerability due to inadequate authorization checks. In versions up to and including 5.9.10, the plugin fails to properly verify user permissions during execution of the run_action_scheduler_task function. This oversight allows unauthenticated attackers to exploit the system by guessing action IDs, enabling them to execute scheduled tasks prematurely or repeatedly. The potential impact includes unauthorized email transmissions, unintended maintenance tasks, or other elevated operations that can disrupt services and consume resources unexpectedly.
Affected Version(s)
Email Subscribers & Newsletters β Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce * <= 5.9.10