Pricing
Case studies
Login
Start trial
Email Subscribers & Newsletters
Icegram
Developer
5.9.21
Latest version
60,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
33 patched
10 Mitigation rules
Authenticated (Administrator+) SQL Injection via 'workflow_ids' Parameter vulnerability
<= 5.9.16
03/03/2026
WordPress Email Subscribers by Icegram Express - Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin <= 5.7.17 - Missing Authorization vulnerability
<= 5.7.17
02/02/2026
Admin+ Stored XSS vulnerability
< 5.7.45
31/12/2025
Admin+ Stored XSS vulnerability
< 5.7.45
31/12/2025
Admin+ Stored XSS vulnerability
< 5.7.45
31/12/2025
Missing Authentication to Unauthenticated Action Scheduler Task Execution vulnerability
<= 5.9.10
12/12/2025
Missing Authentication to Unauthenticated Mailing Queue Trigger vulnerability
<= 5.9.10
18/11/2025
PHP Object Injection vulnerability
<= 5.9.10
08/11/2025
Admin+ Stored XSS in Template vulnerability
< 5.7.50
25/04/2025
Admin+ Stored XSS vulnerability
< 5.7.52
17/04/2025
Admin+ Stored XSS vulnerability
< 5.7.45
13/01/2025
Admin+ SQL Injection vulnerability
< 5.7.44
06/01/2025
Authenticated (Subscriber+) Arbitrary Shortcode Execution vulnerability
<= 5.7.34
02/10/2024
Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure vulnerability
<= 5.7.34
26/09/2024
Missing Authorization vulnerability
<= 5.7.26
17/07/2024
Unauthenticated SQL Injection vulnerability
<= 5.7.25
26/06/2024
Unauthenticated SQL Injection vulnerability
<= 5.7.23
20/06/2024
Authenticated (Subscriber+) SQL Injection Vulnerability via options[list_id] vulnerability
<= 5.7.22
12/06/2024
Unauthenticated SQL Injection via hash vulnerability
<= 5.7.20
05/06/2024
Missing Authorization in handle_ajax_request vulnerability
<= 5.7.19
15/05/2024
Unauthenticated SQL Injection vulnerability
<= 5.7.14
16/04/2024
Authenticated (Administrator+) Cross-Site Scripting via CSV import vulnerability
<= 5.7.15
08/04/2024
Broken Access Control vulnerability
<= 5.7.13
05/04/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.7.11
26/03/2024
Authenticated (Administrator+) Directory Traversal to Arbitrary File Read vulnerability
<= 5.6.23
12/10/2023
CSV Injection
<= 5.5.2
06/02/2023
Unauthenticated email forgery/spoofing vulnerability
<= 4.5.5
10/09/2020
Authenticated SQL injection (SQLi) vulnerability
<= 4.5.0.1
17/07/2020
Cross-Site Request Forgery (CSRF) vulnerability
<= 4.5.0.1
17/07/2020
Multiple security issues
<= 4.2.2
13/11/2019
Cross-Site Scripting (XSS) vulnerability
<= 4.1.6
14/08/2019
Missing Function Level Access Control vulnerability
<= 3.4.7
19/01/2018
Multiple Vulnerabilities
<= 2.9
10/08/2015