PatchSiren cyber security CVE debrief
CVE-2026-12757 icegram CVE debrief
The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
- Vendor
- icegram
- Product
- Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent potential exploitation. They should verify plugin versions and apply patches or updates to prevent exploitation. Additionally, they should review and restrict user permissions to prevent unauthorized shortcode execution, and implement additional monitoring and logging to detect potential exploitation attempts.
Why it matters
CVE-2026-12757 is a medium-severity vulnerability in the Email Subscribers & Newsletters Plugin for WordPress, allowing unauthenticated attackers to execute arbitrary shortcodes. WordPress site administrators and security teams should assess exposure and apply patches or mitigations to prevent potential exploitation.
- Unauthenticated attackers can execute arbitrary shortcodes, potentially leading to malicious content injection or other unintended behavior
- Successful exploitation could allow attackers to manipulate content or inject malicious code
- Site administrators and security teams should verify plugin versions and apply patches or updates to prevent exploitation
Technical summary
The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. The vulnerability allows unauthenticated attackers to execute arbitrary shortcodes, potentially leading to malicious content injection or other unintended behavior. Successful exploitation could allow attackers to manipulate content or inject malicious code.
Defensive priority
Medium priority for WordPress site administrators and security teams to assess exposure and apply patches or mitigations.
Recommended defensive actions
- Assess exposure by checking if the vulnerable plugin version is in use
- Apply patches or updates to the plugin to fix the vulnerability
- Monitor for potential exploitation attempts
- Review and restrict user permissions to prevent unauthorized shortcode execution
- Perform a thorough review of plugin configurations and user permissions
- Implement additional monitoring and logging to detect potential exploitation attempts
- Verify that all necessary security updates and patches are applied
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and references to source code. The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. Evidence is limited to CVE and NVD information;
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12757 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12757
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12757 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12757
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/classes/class-es-handle-subscription.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/classes/class-es-mailer.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/workflows/actions/class-es-action-send-email.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/classes/class-es-handle-subscription.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/classes/class-es-mailer.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/workflows/actions/class-es-action-send-email.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.