The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access the API (provided it is enabled) and add, edit, and delete audience users.
We have discovered 10,521 live websites that are affected by CVE-2024-5703.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 10,521 live websites (41.13% of Email Subscribers install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 183 versions ( 84.72% of all versions) |
![]() | 4,705 websites |
![]() | 1,013 websites |
![]() | 572 websites |
![]() | 386 websites |
![]() | 231 websites |
![]() | 229 websites |
![]() | 223 websites |
![]() | 210 websites |
![]() | 192 websites |
![]() | 188 websites |
.com | 5,267 websites |
.org | 665 websites |
.de | 338 websites |
.com.au | 323 websites |
.net | 253 websites |
.co.uk | 242 websites |
.fr | 187 websites |
.nl | 175 websites |
.com.br | 156 websites |
.ru | 145 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.net | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***.cz | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
**********.net | ![]() | **,*** | |
************.com | ![]() | **,*** | |
**********.***.cn | ![]() | **,*** |
FAQ