The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the content of private, password protected, pending, and draft posts and pages.
We have discovered 12,085 live websites that are affected by CVE-2024-8771.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 12,085 live websites (47.25% of Email Subscribers install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 191 versions ( 88.43% of all versions) |
![]() | 5,512 websites |
![]() | 1,156 websites |
![]() | 666 websites |
![]() | 448 websites |
![]() | 264 websites |
![]() | 258 websites |
![]() | 251 websites |
![]() | 243 websites |
![]() | 217 websites |
![]() | 206 websites |
.com | 6,089 websites |
.org | 769 websites |
.de | 396 websites |
.com.au | 357 websites |
.net | 292 websites |
.co.uk | 277 websites |
.fr | 223 websites |
.nl | 205 websites |
.com.br | 177 websites |
.ru | 160 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.net | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*************.com | ![]() | **,*** | |
***.cz | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
**********.net | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
************.com | ![]() | **,*** |
FAQ