
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14904 is a Cross-Site Request Forgery (CSRF) vulnerability in the Newsletter Email Subscribe plugin for WordPress, affecting versions up to and including 2.4. The flaw stems from incorrect nonce validation in the nels_settings_page function, allowing unauthenticated attackers to modify plugin settings by tricking a site administrator into clicking a malicious link. It was published on January 7, 2026, with Wordfence as the reporting CNA. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence).
The root cause is improper nonce validation (CWE-352) in the nels_settings_page function of the Newsletter Email Subscribe plugin. WordPress nonces are used to verify the authenticity of requests; when validation is incorrect or absent, an attacker can craft a forged HTTP request that the server accepts as legitimate. Exploitation requires social engineering — the attacker must lure an authenticated administrator into triggering the forged request (e.g., by clicking a crafted link or visiting a malicious page), at which point the plugin's settings are updated without the administrator's knowledge. The vulnerable code path is visible in the plugin source at line 109 of newsletter-email-subscribe.php version 2.4 (Plugin Source, Wordfence).
Successful exploitation allows an unauthenticated attacker to modify the Newsletter Email Subscribe plugin's settings on the affected WordPress site, impacting integrity. There is no direct confidentiality or availability impact, as the attacker cannot read data or disrupt service through this vector alone. However, manipulated plugin settings could be leveraged to redirect newsletter subscriptions, inject malicious content into email campaigns, or alter subscriber management behavior, potentially affecting site users and reputation (Wordfence).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-14904. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction from a privileged user (site administrator), which limits opportunistic mass exploitation (Wordfence).
nels_settings_page function with desired plugin settings (e.g., altered email addresses or notification settings), exploiting the missing/incorrect nonce check./wp-admin/admin.php?page=nels_settings_page or similar) from unusual referrers or at unusual times.wp_options table entries related to the Newsletter Email Subscribe plugin) that do not correspond to administrator activity.Referer header points to an unknown external domain.WordPress site administrators should update the Newsletter Email Subscribe plugin to version 2.5 or later, which addresses the improper nonce validation. Until an update can be applied, administrators should exercise caution when clicking links in emails or visiting untrusted websites while logged into the WordPress admin panel. Disabling the plugin temporarily is also a viable workaround if the update cannot be applied immediately (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."