CVE-2026-1925Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'update_template_data' function in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify the title of any post on the site, including posts, pages, and custom post types.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-18: 3Technical Details · 2026-02-18: 202-18
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1925 WordPress EmailKit Plugin Unauthorized Post Title Modification Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1925

    Post summary

    The post identifies CVE‑2026‑1925 as an unauthorized post title modification issue in the WordPress EmailKit plugin, but offers no further details on exploitation or remediation.

    0000020
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1925 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1925 #CVE-2026-1925 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/ngtynZiFnh

    Post summary

    The tweet announces a new CVE-2026-1925 affecting WordPress with a moderate severity rating of 4.3, but provides no further technical details, PoC, or exploitation evidence.

    0000042
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1925 The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the 'upda… https://www.cve.org/CVERecord?id=CVE-2026-1925

    Post summary

    The post announces a missing capability check in the EmailKit plugin that allows unauthorized data modification; no PoC, exploit, patch, or evidence of active exploitation is provided.

    00000137
    56.4K followersView on X

Explore more