CVE-2025-14348 | weMail Plugin up to 2.0.7 on WordPress HTTP Header x-wemail-user authorization
A vulnerability was found in weMail Plugin up to 2.0.7 on WordPress. It has been rated as problematic. The affected element is an unknown function of the component HTTP Header Handler. The manipulation of the argument x-wemail-user leads to authorization bypass.
This vulnerability is documented as CVE-2025-14348. The attack can be initiated remotely. There is not any exploit available.