Vulnerability Description
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and including, 5.7.17. This makes it possible for authenticated attackers, with subscriber access and above, to obtain the contents of private and password-protected posts.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/email-subscribers/trunk/lite/admin/cl
- https://plugins.trac.wordpress.org/browser/email-subscribers/trunk/lite/includes
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5a56e621-2508-4500-b86
- https://plugins.trac.wordpress.org/browser/email-subscribers/trunk/lite/admin/cl
- https://plugins.trac.wordpress.org/browser/email-subscribers/trunk/lite/includes
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5a56e621-2508-4500-b86
FAQ
What is CVE-2024-3626?
CVE-2024-3626 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capab...
How severe is CVE-2024-3626?
CVE-2024-3626 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-3626?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.