PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12757 icegram CVE debrief

The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Vendor
icegram
Product
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent potential exploitation. They should verify plugin versions and apply patches or updates to prevent exploitation. Additionally, they should review and restrict user permissions to prevent unauthorized shortcode execution, and implement additional monitoring and logging to detect potential exploitation attempts.

Why it matters

CVE-2026-12757 is a medium-severity vulnerability in the Email Subscribers & Newsletters Plugin for WordPress, allowing unauthenticated attackers to execute arbitrary shortcodes. WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent potential exploitation.

  • Unauthenticated attackers can execute arbitrary shortcodes, potentially leading to malicious content injection or other unintended behavior
  • Successful exploitation could allow attackers to manipulate content or inject malicious code
  • Site administrators and security teams should verify plugin versions and apply patches or updates to prevent exploitation

Technical summary

The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. The vulnerability allows unauthenticated attackers to execute arbitrary shortcodes, potentially leading to malicious content injection or other unintended behavior. Successful exploitation could allow attackers to manipulate content or inject malicious code.

Defensive priority

Medium priority for WordPress site administrators and security teams to assess exposure and apply patches or mitigations.

Recommended defensive actions

  • Assess exposure by checking if the vulnerable plugin version is in use
  • Apply patches or updates to the plugin to fix the vulnerability
  • Monitor for potential exploitation attempts
  • Review and restrict user permissions to prevent unauthorized shortcode execution
  • Perform a thorough review of plugin configurations and user permissions
  • Implement additional monitoring and logging to detect potential exploitation attempts
  • Verify that all necessary security updates and patches are applied

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and references to source code. The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. Evidence is limited to CVE and NVD information;

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12757 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12757

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12757 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12757

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/classes/class-es-handle-subscription.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/classes/class-es-mailer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/workflows/actions/class-es-action-send-email.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/classes/class-es-handle-subscription.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/classes/class-es-mailer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/workflows/actions/class-es-action-send-email.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.