PT-2026-21373 · WordPress · Webmail
Angus Girvan
·
Published
2026-02-21
·
Updated
2026-02-21
·
CVE-2025-14339
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress versions through 2.0.7
Description
The weMail plugin for WordPress is affected by a flaw allowing unauthorized deletion of forms. The
Forms::permission() function inadequately validates the X-WP-Nonce header, failing to verify user capabilities. The REST nonce is accessible to unauthenticated visitors through the weMail JavaScript object on pages containing weMail forms. This allows any unauthenticated user to permanently delete all weMail forms by obtaining the nonce from the page source and sending a DELETE request to the forms endpoint: /wp-json/wemail/v1/forms. The vulnerable parameter is the X-WP-Nonce header.Recommendations
Update to a version of the weMail plugin later than 2.0.7.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webmail