CVE-2024-4010
Email Subscribers by Icegram Express <= 5.7.19 - Missing Authorization in handle_ajax_request
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to cause a loss of confidentiality, integrity, and availability, by performing multiple unauthorized actions. Some of these actions could also be leveraged to conduct PHP Object Injection and SQL Injection attacks.
| CWE | CWE-862 |
| Vendor | icegram |
| Product | email subscribers & newsletters – email marketing, post notifications & newsletter plugin for wordpress |
| Published | May 15, 2024 |
| Last Updated | Apr 8, 2026 |
Get instant alerts for icegram email subscribers & newsletters – email marketing, post notifications & newsletter plugin for wordpress
Be the first to know when new high vulnerabilities affecting icegram email subscribers & newsletters – email marketing, post notifications & newsletter plugin for wordpress are published — delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H