CVE-2025-14348 Details
Description
The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.7. This is due to the plugin's REST API trusting the `x-wemail-user` HTTP header to identify users without verifying the request originates from an authenticated WordPress session. This makes it possible for unauthenticated attackers who know or can guess an admin email (easily enumerable via `/wp-json/wp/v2/users`) to impersonate that user and access the CSV subscriber endpoints, potentially exfiltrating subscriber PII (emails, names, phone numbers) from imported CSV files.
A vulnerability allowing authorization bypass has been identified in the weMail WordPress plugin, specifically in versions through 2.0.7. The issue arises because the plugin's REST API relies on the 'x-wemail-user' HTTP header for user identification, without confirming that the request comes from an authenticated WordPress session. This flaw enables unauthenticated attackers who can guess or know an admin's email—easily obtainable from the WordPress REST API user endpoint—to impersonate that user. Exploitation of this vulnerability allows access to CSV subscriber endpoints, potentially leading to the unauthorized extraction of personal information, such as emails, names, and phone numbers, from CSV files imported into the plugin.
Users are advised to update the weMail WordPress plugin to version 2.0.8 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 20, 2026CISA-ADP
Assessed Jan 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| weDevs weMail | <= 2.0.7 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 20, 2026 | New CVE Received | [email protected] |
Volerion