CVE-2024-12311: Email Subscribers < 5.7.44 - Admin+ SQL Injection
Published Jan 6, 2025
·Updated
The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
Affected Software
2 affected components
Icegram Email Subscribers<5.7.44
Icegram Email Subscribers \& Newsletters Wordpress<5.7.44
Event History
Jan 6, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-12311?
CVE-2024-12311 is considered a high-severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-12311?
To fix CVE-2024-12311, update the Email Subscribers by Icegram Express WordPress plugin to version 5.7.44 or later.
3
What software is affected by CVE-2024-12311?
CVE-2024-12311 affects the Email Subscribers by Icegram Express WordPress plugin versions prior to 5.7.44.
4
What type of attack can be executed through CVE-2024-12311?
CVE-2024-12311 allows for SQL injection attacks due to improper sanitization of user inputs.
5
Who is the vendor for the product affected by CVE-2024-12311?
The vendor for the affected product is Icegram.