CVE-2025-66055: WordPress Email Subscribers & Newsletters plugin <= 5.9.10 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66055?
CVE-2025-66055 has a high severity rating due to the potential for remote code execution through object injection.
How do I fix CVE-2025-66055?
To fix CVE-2025-66055, update the Icegram Email Subscribers & Newsletters plugin to version 5.9.11 or later.
What is the impact of CVE-2025-66055?
The impact of CVE-2025-66055 could allow an attacker to execute arbitrary code on the server through deserialization of untrusted data.
Which software versions are affected by CVE-2025-66055?
CVE-2025-66055 affects Icegram Email Subscribers & Newsletters versions up to and including 5.9.10.
Is CVE-2025-66055 specific to any CMS?
Yes, CVE-2025-66055 specifically affects the Icegram Email Subscribers & Newsletters plugin used within WordPress.