CVE-2024-5756

Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 10,002 live websites that are affected by CVE-2024-5756.

Test my site




Affected Software

Product  Email Subscribers
Category Wordpress Plugins
Vulnerable Domains10,002 live websites (39.10% of Email Subscribers install base)
Vulnerable Versions
  • from 0 through 5.7.23
Vulnerable Versions Count180 versions ( 83.33% of all versions)



Details

  • Published - Jun 21, 2024
  • Updated - Aug 1, 2024

Credits

  • Arkadiusz Hydzik (finder)

CVE-2024-5756 usage by Country

United States4,463 websites



Germany952 websites
France543 websites
GB369 websites
Cyprus219 websites
Netherlands217 websites
Australia215 websites
Spain202 websites
Canada188 websites
Russia185 websites

CVE-2024-5756 usage by TLD

.com5,009 websites
.org632 websites
.com.au317 websites
.de315 websites
.net239 websites
.co.uk229 websites
.fr175 websites
.nl167 websites
.com.br151 websites
.ru142 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-5756

Top websites that are affected by CVE-2024-5756. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States**,***
***************.com United States**,***
***********.com United States**,***
*************.com Singapore**,***
***.cz Czech Republic**,***
**********.com United States**,***
******.com United States**,***
**********.net United States**,***
************.com United States**,***
**********.***.cn United States**,***
See full domain list

FAQ

A total of 10,002 websites have been identified as vulnerable to CVE-2024-5756, discovered through global website indexing conducted by WebTechSurvey.
Email Subscribers is susceptible to CVE-2024-5756 vulnerability.
Email Subscribers versions before, and including, 5.7.23 are vulnerable to CVE-2024-5756.