PT-2025-1897 · Icegram Express · Email Subscribers

Dmitry Ignatyev

·

Published

2025-01-13

·

Updated

2025-05-08

·

CVE-2024-12567

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Email Subscribers by Icegram Express WordPress plugin versions prior to 5.7.45
Description The issue concerns a Stored Cross-Site Scripting vulnerability. It could allow high-privilege users, such as admins, to perform attacks even when the unfiltered html capability is disallowed, for example, in a multisite setup. There is no information provided about a public exploit or whether the vulnerability has been exploited by attackers. The vulnerability can be exploited by high-privilege users and does not require the unfiltered html capability to be enabled. No information is available about the number of Internet users that can be affected by the exploitation of this vulnerability.
Recommendations For versions prior to 5.7.45, update to version 5.7.45 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's form settings to minimize the risk of exploitation. Avoid using the vulnerable form settings in the plugin until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-12567

Affected Products

Email Subscribers