DirectIQ Email Marketing
DirectIQ Email Marketing has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is SQL Injection, behind 1 of the records (100%).
The one issue recorded for DirectIQ Email Marketing has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Kim Sang. DirectIQ Email Marketing is installed on roughly 30 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.9.16.
CVE-2025-52829DirectIQ Email Marketing <= 2.0 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

DirectIQ Email Marketing
Author
DirectIQ
DirectIQ offers a free email marketing platform for small businesses. With our new plugin you can easily create and embed DirectIQ Email Marketing sign up forms into your posts and pages, without having to write a single line of code. More information Please visit the our website at DirectIQ for more information. Asked Questions Write your query and suggestion Regarding different features on the FAQ page on the plugin website. Support? For support questions, bug reports, or feature requests, please use the WordPress Support Forums. Please search through the forums first, and only create a new topic if you don’t find an existing answer. Thank you! Requirements? In short: WordPress 5.2 or higher, while the latest version of WordPress is always recommended. Privacy Notices With the default configuration, this plugin, in itself, does not: track users by stealth; write any user personal data to the database; send any data to external servers; use cookies. Plugin sends only those data fill in the signup form to third party api (DirectIQ). Version 1.1 Remove place holder from form input fields. Version 1.2 Add HTML embedded form code. Now form can be place other site Version 1.2.1 HTML embedded form submit success message will come from what admin has setup success message for the form. Version 1.2.2 Allow to show / hide form name. It can be done during edit/add form. Version 1.2.3 Allow to change submit button text Version 1.2.4 WordPress left side bar overlap css issue. Version 1.2.5 Woocommerce admin dashboard css confliction issue. Version 1.2.6 Translation field given in plugin admin for required field. Version 2.0 Completely new changes to the UI and added new pages for navigation through plugin.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C