CubeCart Unauthorized Newsletter Unsubscription via force_unsubscribe Parameter
Vulnerability Description
CubeCart is an ecommerce software solution. Prior to version 6.5.11, a logic flaw exists in the newsletter subscription endpoint that allows an attacker to unsubscribe any user without their consent. By changing the value of the force_unsubscribe parameter in the POST request to 1, an attacker can force the removal of any valid subscriber’s email address. This issue has been patched in version 6.5.11.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59413
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/cubecart/v6/security/advisories/GHSA-869v-gjv8-9m7f
- https://github.com/cubecart/v6/commit/7fd1cd04f5d5c3ce1d7980327464f0ff6551de79
- https://github.com/cubecart/v6/commit/db965fcfa260c4f17eb16f8c5494e5af4a8ac271
- https://github.com/cubecart/v6/commit/dbc58cf1f7a6291f7add5893b56bff7920a29128
More from cubecart
View All →Affected Vendor
cubecart
View all reports →