CVE-2024-5703

Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access the API (provided it is enabled) and add, edit, and delete audience users.


We have discovered 10,521 live websites that are affected by CVE-2024-5703.

Test my site




Affected Software

Product  Email Subscribers
Category Wordpress Plugins
Vulnerable Domains10,521 live websites (41.13% of Email Subscribers install base)
Vulnerable Versions
  • from 0 through 5.7.26
Vulnerable Versions Count183 versions ( 84.72% of all versions)



Details

  • Published - Jul 17, 2024
  • Updated - Aug 1, 2024

Credits

  • Arkadiusz Hydzik (finder)

CVE-2024-5703 usage by Country

United States4,705 websites



Germany1,013 websites
France572 websites
GB386 websites
Cyprus231 websites
Netherlands229 websites
Australia223 websites
Spain210 websites
Canada192 websites
Russia188 websites

CVE-2024-5703 usage by TLD

.com5,267 websites
.org665 websites
.de338 websites
.com.au323 websites
.net253 websites
.co.uk242 websites
.fr187 websites
.nl175 websites
.com.br156 websites
.ru145 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5703

Top websites that are affected by CVE-2024-5703. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States**,***
***************.com United States**,***
***********.com United States**,***
*************.com Singapore**,***
***.cz Czech Republic**,***
**********.com United States**,***
******.com United States**,***
**********.net United States**,***
************.com United States**,***
**********.***.cn United States**,***
See full domain list

FAQ

A total of 10,521 websites have been identified as vulnerable to CVE-2024-5703, discovered through global website indexing conducted by WebTechSurvey.
Email Subscribers is susceptible to CVE-2024-5703 vulnerability.
Email Subscribers versions before, and including, 5.7.26 are vulnerable to CVE-2024-5703.