CVE-2024-5703: Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access the API (provided it is enabled) and add, edit, and delete audience users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automationto a version that resolves this vulnerability.Fixed in 5.7.26
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5703?
CVE-2024-5703 is considered a medium severity vulnerability due to unauthorized API access possibilities.
How do I fix CVE-2024-5703?
To fix CVE-2024-5703, update the Icegram Email Subscribers & Newsletters plugin to version 5.7.27 or later.
What software is affected by CVE-2024-5703?
CVE-2024-5703 affects all versions of the Icegram Email Subscribers & Newsletters plugin for WordPress up to and including version 5.7.26.
What type of vulnerability is CVE-2024-5703?
CVE-2024-5703 is an unauthorized API access vulnerability due to a missing capability check.
Who is the vendor for CVE-2024-5703?
The vendor for CVE-2024-5703 is Icegram, the creator of the Email Subscribers & Newsletters plugin.