{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/icegram/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:icegram:email_subscribers:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-2876"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Email Subscribers (\u003c= 5.7.14)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","sql-injection","cve-2024-2876"],"_cs_type":"advisory","_cs_vendors":["Icegram"],"content_html":"\u003cp\u003eCVE-2024-2876 is a critical security vulnerability identified in the Email Subscribers by Icegram Express plugin for WordPress. The flaw, which carries a CVSS score of 9.8, stems from insufficient input sanitization and inadequate parameter preparation within the IG_ES_Subscribers_Query class. An unauthenticated attacker can exploit this via the advanced_filter parameter in crafted HTTP POST requests to the plugin's endpoint. Successful exploitation allows for the execution of arbitrary SQL queries against the underlying database, facilitating unauthorized information extraction and modification. The vulnerability affects all versions of the plugin up to and including 5.7.14. Organizations utilizing this plugin are advised to upgrade to version 5.7.15 or later immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site with the vulnerable Email Subscribers plugin installed.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting /wp-admin/admin-post.php.\u003c/li\u003e\n\u003cli\u003eAttacker includes specific parameters: page=es_subscribers, is_ajax=1, and action=_sent.\u003c/li\u003e\n\u003cli\u003eAttacker injects malicious SQL payloads into the advanced_filter[conditions][0][0][field] parameter.\u003c/li\u003e\n\u003cli\u003eThe server-side code in IG_ES_Subscribers_Query processes the request without sufficient validation.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL command, such as a UNION SELECT with a time-based delay (e.g., SLEEP).\u003c/li\u003e\n\u003cli\u003eThe attacker parses the server's response to confirm successful injection or exfiltrate data from the database.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-2876 provides an unauthenticated attacker with the ability to perform full database extraction, modification, or destruction. Given the sensitive nature of email subscriber databases, this includes the theft of user lists, personal identifiers, and other stored content, impacting the privacy and integrity of the affected organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Email Subscribers by Icegram Express plugin to version 5.7.15 or the latest available version immediately.\u003c/li\u003e\n\u003cli\u003eDeploy the WAF rule below to identify and block exploit attempts targeting the advanced_filter parameter.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests to /wp-admin/admin-post.php containing SQL syntax characters (e.g., union, select, sleep).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T01:48:17Z","date_published":"2026-09-03T01:48:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-2876/","summary":"CVE-2024-2876 is an unauthenticated SQL injection vulnerability in the Email Subscribers by Icegram Express plugin for WordPress, allowing remote attackers to extract database content via improper input sanitization.","title":"Unauthenticated SQL Injection in Email Subscribers by Icegram Express","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-2876/"}],"language":"en","title":"CraftedSignal Threat Feed - Icegram","version":"https://jsonfeed.org/version/1.1"}