Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce, CVE-2024-4010
- CVE, Research URL
- Home page URL
- Application
-
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce
- Published on
- May 15, 2024
- Research Description
- The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to cause a loss of confidentiality, integrity, and availability, by performing multiple unauthorized actions. Some of these actions could also be leveraged to conduct PHP Object Injection and SQL Injection attacks.
- Affected versions
-
Min -, max 5.7.20.
- Status
-
vulnerable