Email Subscribers Vulnerable to Time-Based SQL Injection
CVE-2024-5756
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 21 June 2024
Summary
The Email Subscribers by Icegram Express plugin for WordPress, used for email marketing and automation, contains a vulnerability that allows for time-based SQL Injection. The flaw exists due to insufficient escaping of the user-supplied 'db' parameter and inadequate preparation of SQL queries in all versions up to 5.7.23. This weakness permits unauthenticated attackers to insert additional SQL commands into existing queries, potentially leading to the exposure of sensitive data stored within the WordPress database. It is crucial for users of this plugin to review their security measures and apply necessary updates to mitigate this risk.
Affected Version(s)
Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce * <= 5.7.23
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved