Stored Cross-Site Scripting in Email Subscribers by Icegram Express Plugin
CVE-2024-12566
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 13 January 2025
Badges
Summary
The Email Subscribers by Icegram Express WordPress plugin prior to version 5.7.45 is susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability arises from a failure to properly sanitize and escape certain form settings, enabling high privilege users, such as administrators, to inject malicious scripts. This issue persists even when the unfiltered_html capability is disabled, making it particularly concerning in multisite setups where stringent controls on user capabilities are expected.
Affected Version(s)
Email Subscribers by Icegram Express 0 < 5.7.45
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved