cleantalk
Vulnerabilities and Security Researches

Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce, fd56191a-8a01-4ae4-a1f1-61a6ac210325

Published on
-
Research Description
Email Subscribers &amp; Newsletters &#8211; Email Marketing, Post Notifications &amp; Newsletter Plugin for WordPress [email-subscribers] < 5.3.2 Email Subscribers &amp; Newsletters &lt; 5.3.2 - Unauthenticated arbitrary option update The plugin lacks both authentication and nonce checks in its `es_dismiss_admin_notice` function, allowing an external attacker to set arbitrary plugin options to &quot;yes&quot;.
Affected versions
max 5.3.2.
Status
vulnerable