CVE-2026-1651
- EPSS 0.03%
- Veröffentlicht 04.03.2026 01:22:00
- Zuletzt bearbeitet 04.03.2026 18:08:05
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' parameter in all versions up to, and including, 5.9.16 due to insufficient escaping on the user supplied parameter and lack of suffici...
CVE-2025-12348
- EPSS 0.1%
- Veröffentlicht 12.12.2025 09:20:29
- Zuletzt bearbeitet 12.12.2025 15:17:31
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is author...
CVE-2025-66055
- EPSS 0.07%
- Veröffentlicht 21.11.2025 12:29:53
- Zuletzt bearbeitet 20.01.2026 15:19:00
Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.
CVE-2025-12349
- EPSS 0.12%
- Veröffentlicht 19.11.2025 04:28:18
- Zuletzt bearbeitet 19.11.2025 19:14:59
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Authorization in versions up to, and including, 5.9.10. This is due to the plugin not properly verifying that a user is authorized to ...
CVE-2024-8254
- EPSS 0.29%
- Veröffentlicht 02.10.2024 07:15:03
- Zuletzt bearbeitet 08.10.2024 19:08:41
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the softw...
CVE-2024-5703
- EPSS 0.23%
- Veröffentlicht 17.07.2024 08:15:02
- Zuletzt bearbeitet 21.11.2024 09:48:12
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7....
CVE-2024-6172
- EPSS 2.3%
- Veröffentlicht 02.07.2024 07:15:04
- Zuletzt bearbeitet 21.11.2024 09:49:07
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to in...
CVE-2024-37252
- EPSS 0.13%
- Veröffentlicht 26.06.2024 11:15:51
- Zuletzt bearbeitet 21.11.2024 09:23:28
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.
CVE-2024-31352
- EPSS 0.36%
- Veröffentlicht 09.06.2024 18:15:10
- Zuletzt bearbeitet 21.11.2024 09:13:21
Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.
CVE-2024-4295
- EPSS 92.8%
- Veröffentlicht 05.06.2024 06:15:12
- Zuletzt bearbeitet 21.11.2024 09:42:33
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient prep...