A vulnerability identified as critical has been detected in Icegram Express Email Subscribers Plugin up to 5.9.16 on WordPress. This issue affects some unknown processing. The manipulation of the argument workflow_ids leads to sql injection.
This vulnerability is traded as CVE-2026-1651. It is possible to initiate the attack remotely. There is no exploit available.