cleantalk
Vulnerabilities and Security Researches

Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce, CVE-2024-12311

CVE, Research URL

CVE-2024-12311

Published on
Jan 06, 2025
Research Description
The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected versions
Min -, max 5.7.44.
Status
vulnerable