CVE-2024-8771

Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive data including the content of private, password protected, pending, and draft posts and pages.


We have discovered 12,085 live websites that are affected by CVE-2024-8771.

Test my site




Affected Software

Product  Email Subscribers
Category Wordpress Plugins
Vulnerable Domains12,085 live websites (47.25% of Email Subscribers install base)
Vulnerable Versions
  • from 0 through 5.7.34
Vulnerable Versions Count191 versions ( 88.43% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Sep 26, 2024
  • Updated - Sep 26, 2024

Credits

  • Michelle Porter (finder)

CVE-2024-8771 usage by Country

United States5,512 websites



Germany1,156 websites
France666 websites
GB448 websites
Netherlands264 websites
Cyprus258 websites
Australia251 websites
Spain243 websites
Canada217 websites
Russia206 websites

CVE-2024-8771 usage by TLD

.com6,089 websites
.org769 websites
.de396 websites
.com.au357 websites
.net292 websites
.co.uk277 websites
.fr223 websites
.nl205 websites
.com.br177 websites
.ru160 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-8771

Top websites that are affected by CVE-2024-8771. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States**,***
***************.com United States**,***
***********.com United States**,***
*************.com Singapore**,***
***.cz Czech Republic**,***
**********.com United States**,***
******.com United States**,***
**********.net United States**,***
*********.com United States**,***
************.com United States**,***
See full domain list

FAQ

CVE-2024-8771 is Missing Authorization in Email Subscribers
A total of 12,085 websites have been identified as vulnerable to CVE-2024-8771, discovered through global website indexing conducted by WebTechSurvey.
Email Subscribers is susceptible to CVE-2024-8771 vulnerability.
Email Subscribers versions before, and including, 5.7.34 are vulnerable to CVE-2024-8771.