CVE-2024-12566: Email Subscribers < 5.7.45 - Admin+ Stored XSS
The Email Subscribers by Icegram Express WordPress plugin before 5.7.45 does not sanitise and escape some of form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12566?
CVE-2024-12566 is considered to have a high severity due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-12566?
To mitigate CVE-2024-12566, update the Icegram Email Subscribers plugin to version 5.7.45 or later.
Who is affected by CVE-2024-12566?
CVE-2024-12566 affects users of the Icegram Email Subscribers plugin prior to version 5.7.45.
What are the potential impacts of CVE-2024-12566?
CVE-2024-12566 can allow high privilege users to execute malicious scripts, compromising the security of the website.
Is it safe to use the Icegram Email Subscribers plugin if I cannot update to the latest version due to compatibility issues?
If you cannot update the plugin due to compatibility issues, consider disabling the plugin or implementing additional security measures to mitigate the risk associated with CVE-2024-12566.