CVE-2024-8254: Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8254?
CVE-2024-8254 is classified as a medium severity vulnerability due to the potential for arbitrary shortcode execution.
How do I fix CVE-2024-8254?
To remediate CVE-2024-8254, update the Email Subscribers by Icegram plugin to version 5.7.35 or later.
Who is affected by CVE-2024-8254?
All users of the Email Subscribers by Icegram plugin for WordPress up to and including version 5.7.34 are affected by CVE-2024-8254.
What type of vulnerability is CVE-2024-8254?
CVE-2024-8254 is an arbitrary shortcode execution vulnerability.
When was CVE-2024-8254 disclosed?
CVE-2024-8254 was disclosed in October 2024.