CVE-2026-12757: Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field
The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin "Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin"to a version that resolves this vulnerability.Fixed in 5.9.27
Event History
Frequently Asked Questions
Which installations are affected?
WordPress sites using the Email Subscribers & Newsletters plugin in version 5.9.27 or any earlier version are affected.
Does exploitation require a WordPress account or user interaction?
No. The vulnerability is unauthenticated and requires no user interaction; the attack vector is network-accessible.
What is the expected security impact?
An attacker can execute arbitrary shortcodes through the subscriber name field. The supplied severity vector indicates low confidentiality impact and low integrity impact, with no availability impact.