CVE-2026-83555: Email Subscribers by Icegram Express < 5.9.35 - Unauthenticated Subscription Status Change via Missing Token Verification
Published Sep 23, 2026
·Updated
The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know.
Affected Software
1 affected component
Icegram Email Subscribers & Newsletters<5.9.35
Event History
Sep 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated user can exploit it. They need to know the email address of the subscriber whose status they want to change.
2
What subscriber actions can an attacker force?
An attacker can force-unsubscribe a subscriber or force-confirm their subscription status. The issue affects arbitrary subscribers when their email addresses are known.
3
What versions are affected?
Versions of Icegram Email Subscribers & Newsletters before 5.9.35 are affected.