CVE-2024-4295

Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 9,755 live websites that are affected by CVE-2024-4295.

Test my site




Affected Software

Product  Email Subscribers
Category Wordpress Plugins
Vulnerable Domains9,755 live websites (38.14% of Email Subscribers install base)
Vulnerable Versions
  • from 0 through 5.7.20
Vulnerable Versions Count176 versions ( 81.48% of all versions)



Details

  • Published - Jun 5, 2024
  • Updated - Aug 1, 2024

Credits

  • 1337_Wannabe (finder)

CVE-2024-4295 usage by Country

United States4,351 websites



Germany925 websites
France528 websites
GB361 websites
Netherlands213 websites
Cyprus212 websites
Australia210 websites
Spain194 websites
Canada182 websites
Russia181 websites

CVE-2024-4295 usage by TLD

.com4,887 websites
.org615 websites
.com.au314 websites
.de309 websites
.net231 websites
.co.uk223 websites
.fr168 websites
.nl164 websites
.com.br145 websites
.ru140 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4295

Top websites that are affected by CVE-2024-4295. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States**,***
***************.com United States**,***
***********.com United States**,***
*************.com Singapore**,***
***.cz Czech Republic**,***
**********.com United States**,***
******.com United States**,***
**********.net United States**,***
************.com United States**,***
**********.***.cn United States**,***
See full domain list

FAQ

A total of 9,755 websites have been identified as vulnerable to CVE-2024-4295, discovered through global website indexing conducted by WebTechSurvey.
Email Subscribers is susceptible to CVE-2024-4295 vulnerability.
Email Subscribers versions before, and including, 5.7.20 are vulnerable to CVE-2024-4295.