PT-2024-37083 · Icegram Express · Email Subscribers

Arkadiusz Hydzik

·

Published

2024-07-17

·

Updated

2024-07-19

·

CVE-2024-5703

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin versions up to, and including, 5.7.26
Description: The issue is related to unauthorized API access due to a missing capability check. This allows authenticated attackers with Subscriber-level access and above to access the API, if enabled, and perform actions such as adding, editing, and deleting audience users.
Recommendations: For versions up to, and including, 5.7.26, update to a version that includes a fix for the missing capability check to prevent unauthorized API access. As a temporary workaround, consider disabling the API access until a patch is available. Restrict access to the API to minimize the risk of exploitation by only allowing access to trusted users.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-5703

Affected Products

Email Subscribers