CVE-2022-0439Disclosure(icegram / email_subscribers_\&_newsletters)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place for the action, allowing an attacker to trick any logged in user to perform the action by clicking a link.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • email_subscribers_\&_newsletters

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
email_subscribers_\&_newsletters

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-25: 1Technical Details · 2026-02-25: 102-25
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2022-0439 - high 🚨 Email Subscribers & Newsletters <= 5.3.1 - Authenticated SQL Injection > The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly ... 👾 https://cloud.projectdiscovery.io/library/CVE-2022-0439 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE-2022-0439, an authenticated SQL injection in the Email Subscribers & Newsletters WordPress plugin (versions <=5.3.1), and provides a link to a library page for further details.

    00000122
    890 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appicegramemail_subscribers_\&_newsletters-wordpress-

Explore more