Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce, fd56191a-8a01-4ae4-a1f1-61a6ac210325
- CVE, Research URL
- Home page URL
- Application
-
Icegram Express – Email Marketing, Newsletters and Automation for WordPress & WooCommerce
- Published on
- -
- Research Description
- Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress [email-subscribers] < 5.3.2 Email Subscribers & Newsletters < 5.3.2 - Unauthenticated arbitrary option update The plugin lacks both authentication and nonce checks in its `es_dismiss_admin_notice` function, allowing an external attacker to set arbitrary plugin options to "yes".
- Affected versions
-
max 5.3.2.
- Status
-
vulnerable