Skip to content

Critical Vulnerability in WordPress Plugin - 20240607001

Overview

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

What is vulnerable?

CVE Severity CVSS Product(s) Affected
CVE-2024-4295 Critical 9.8 versions up to and including 5.7.20

What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of 48 hours... (refer Patch Management):