CVE-2025-12349: Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue Trigger
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to perform an action in the triggermailingqueuesending function. This makes it possible for unauthenticated attackers to force immediate email sending, bypass the schedule, increase server load, and change plugin state (e.g., last-cron-hit), enabling abuse or DoS-like effects.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12349?
CVE-2025-12349 is rated as a medium severity vulnerability.
How do I fix CVE-2025-12349?
To fix CVE-2025-12349, update the Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin to version 5.9.11 or later.
Who is affected by CVE-2025-12349?
Users of the Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress versions up to 5.9.10 are affected by CVE-2025-12349.
What type of vulnerability is CVE-2025-12349?
CVE-2025-12349 is an authorization vulnerability that allows unauthorized actions to be performed.
When was CVE-2025-12349 disclosed?
CVE-2025-12349 was disclosed in 2025.