Missing Authorization Vulnerability in Icegram Express Plugin for WordPress
CVE-2025-12348

5.3MEDIUM

What is CVE-2025-12348?

The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress has a vulnerability due to inadequate authorization checks. In versions up to and including 5.9.10, the plugin fails to properly verify user permissions during execution of the run_action_scheduler_task function. This oversight allows unauthenticated attackers to exploit the system by guessing action IDs, enabling them to execute scheduled tasks prematurely or repeatedly. The potential impact includes unauthorized email transmissions, unintended maintenance tasks, or other elevated operations that can disrupt services and consume resources unexpectedly.

Affected Version(s)

Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce * <= 5.9.10

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Lukita
.
CVE-2025-12348 : Missing Authorization Vulnerability in Icegram Express Plugin for WordPress