Impact
The flaw in the Email Subscribers & Newsletters plugin allows an unauthenticated user to submit arbitrary text in the subscriber name field, which the plugin forwards directly to WordPress's do_shortcode function without validation. This means the attacker can inject any WordPress shortcode of their choosing and have it executed in the context of the site. The vulnerability therefore enables arbitrary execution of shortcodes, which could be used to run potentially harmful code or manipulate site content, though the CVE description does not explicitly claim full system compromise.
Affected Systems
All installations of the Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress version 5.9.27 and earlier are affected. The issue exists in every release prior to 5.9.28 and can be triggered via the public subscription interface that accepts user‑supplied subscriber names.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the moderate severity range. Because the flaw is reachable through a publicly exposed form and requires no authentication, the attack surface is broad. The EPSS score is unavailable, and the risk is not listed in the CISA KEV catalog, so no confirmed exploits are known; however, the straightforward public‑end access means that exploitation could potentially occur if an attacker discovers the defect.
OpenCVE Enrichment