CVE-2024-2876

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-24: 309-24
Referenced assets1 URL
By indicator
Full discourse3 posts
  • ExploitGrid@exploitgrid

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2026-28576 CVE-2024-2876 CVE-2026-13355 CVE-2026-19658 CVE-2026-41089 ..🧵👇

    2000064
    47 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2024-2876 [CRITICAL/PoC] CVE-2024-2876 🔗 https://exploitgrid.net/exploits/e60e20c6-8500-4bb0-a88a-1f55e7c5ec93

    1000032
    47 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2026-41089 — Netlogon RCE · PoC live ├ CVE-2026-28576 · CVE-2024-2876 · PoC live └ CVE-2026-13355 · CVE-2026-19658 · PoC live +497 more tracked today.

    1000043
    47 followersView on X

Explore more