CVE-2025-49917: WordPress Icegram Express Pro plugin <= 5.9.5 - Server Side Request Forgery (SSRF) vulnerability
Published Oct 22, 2025
·Updated
Server-Side Request Forgery (SSRF) vulnerability in Icegram Icegram Express Pro email-subscribers-premium allows Server Side Request Forgery.This issue affects Icegram Express Pro: from n/a through <= 5.9.5.
Affected Software
1 affected component
Icegram Icegram Express Pro<=5.9.5
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49917?
CVE-2025-49917 is classified as a high severity Server-Side Request Forgery (SSRF) vulnerability.
2
How do I fix CVE-2025-49917?
To fix CVE-2025-49917, update Icegram Express Pro to the latest version beyond 5.9.5.
3
What versions of Icegram Express Pro are affected by CVE-2025-49917?
CVE-2025-49917 affects all versions of Icegram Express Pro from n/a up to and including version 5.9.5.
4
What type of vulnerability is CVE-2025-49917?
CVE-2025-49917 is a Server-Side Request Forgery (SSRF) vulnerability.
5
What can attackers do with CVE-2025-49917?
Attackers exploiting CVE-2025-49917 can potentially make unauthorized requests to internal resources on the server.