Email Subscribers Vulnerable to Time-Based SQL Injection
CVE-2024-5756

9.8CRITICAL

Summary

The Email Subscribers by Icegram Express plugin for WordPress, used for email marketing and automation, contains a vulnerability that allows for time-based SQL Injection. The flaw exists due to insufficient escaping of the user-supplied 'db' parameter and inadequate preparation of SQL queries in all versions up to 5.7.23. This weakness permits unauthenticated attackers to insert additional SQL commands into existing queries, potentially leading to the exposure of sensitive data stored within the WordPress database. It is crucial for users of this plugin to review their security measures and apply necessary updates to mitigate this risk.

Affected Version(s)

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce * <= 5.7.23

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arkadiusz Hydzik
.