CVE-2024-6172
Published
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT
Description
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE-2024-37252 appears to be a duplicate of this issue.
<p><strong>Icegram Express</strong> makes email marketing simple, effective, and fully WordPress native.<br />
This powerful email marketing plugin helps you grow your subscriber list using high converting opt-in forms, send beautiful newsletters, and automate follow-ups all without writing a single line of code.</p>
<p>Built for bloggers, small businesses, and online stores, Icegram Express is an all-in-one solution to engage subscribers, increase conversions, and build long-term relationships directly from your WordPress dashboard.</p>
<p>Grow your impact. Stop worrying about email 📬</p>
<h3>Overview</h3>
<p><strong>Collect leads, build your email list, send newsletters, post notifications, and automated emails all from your WordPress dashboard.</strong></p>
<p><a href="https://www.icegram.com/express/?utm_source=ig_express_wp_readme&utm_medium=mailpoet_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">Icegram Express</a> is a powerful yet beginner-friendly WordPress email marketing and newsletter plugin designed for bloggers, businesses, and WooCommerce stores. It helps you grow subscribers, engage audiences, and convert visitors into loyal customers without recurring SaaS costs.</p>
<p>With Icegram Express, you can:</p>
<ul>
<li>Create and embed <strong>high-converting subscription forms</strong></li>
<li><strong>Automatically send new post notification emails</strong></li>
<li>Send <strong>newsletters and broadcast emails</strong></li>
<li>Automation for welcome emails, follow-ups, Birthday offers, and abandoned cart recovery</li>
<li>Segment lists and target the right subscribers</li>
<li><strong>Easy drag and drop editor to design forms and email campaigns</strong></li>
<li>REST API and tools for developers</li>
</ul>
<p>It works seamlessly with popular themes, plugins, and <strong>SMTP / email service providers</strong>, making setup easy and reliable.</p>
<p><strong>Trusted by 100000+ users</strong>, Icegram Express is a pocket-friendly alternative to expensive tools like Mailchimp, without compromising on features or control.</p>
<p><strong>Icegram Express can be accessed in the following languages:</strong></p>
<ul>
<li>Czech</li>
<li>Dutch</li>
<li>English (UK)</li>
<li>English (US) </li>
<li>German</li>
<li>Hungarian</li>
<li>Polish</li>
<li>Russian</li>
<li>Spanish (Mexico)</li>
<li>Spanish (Spain)</li>
<li>And Spanish (Venezuela) </li>
</ul>
<h3>💌 Why others love Icegram Express?</h3>
<ul>
<li><strong>“Better than Mailchimp – and way cheaper!”</strong> – <a href="https://wordpress.org/support/topic/so-far-so-good-1088/" rel="ugc">brianharper</a></li>
<li><strong>“Grew my subscriber list by 20% in just a month!”</strong> – <a href="https://wordpress.org/support/topic/very-useful-plugin-952/" rel="ugc">fedephyto</a></li>
<li><strong>“Worked where other plugins failed: easy setup and instant results (unlike those big shots!)”</strong> – <a href="https://wordpress.org/support/topic/worked-where-other-subscriber-plugins-failed/" rel="ugc">laurendevine</a></li>
<li><strong>“Best customer support I’ve ever experienced – both on free and paid plans”</strong> – <a href="https://wordpress.org/support/topic/a-helpful-plug-in/" rel="ugc">chaffeeb</a></li>
<li><strong>“Plugin with 50+ features & 5-minute setup!”</strong> – <a href="https://wordpress.org/support/topic/awesome-email-subscribers-newsletters/" rel="ugc">joanyedwards</a></li>
<li><strong>“Best plugin for post notifications and Newsletter broadcasting!”</strong> – <a href="https://wordpress.org/support/topic/best-plugin-for-post-notifications-and-newsletter-broadcasting/" rel="ugc">Roopesh Jain</a></li>
</ul>
<p>Icegram Express earns praise for being a high-quality email marketing automation plugin, offering speed, ease of use, reliability, and excellent support.</p>
<p>BTW, once people start using Icegram Express, they keep using it as they grow. Many users have been with us for over 9 years.</p>
<p>Explore how Icegram Express compares with others like <a href="https://www.icegram.com/mailpoet-review/?utm_source=ig_express_wp_readme&utm_medium=mailpoet_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">MailPoet</a> and <a href="https://www.icegram.com/fluentcrm-review/?utm_source=ig_express_wp_readme&utm_medium=fluentcrm_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">FluentCRM</a>.</p>
<p>👉👉👉 Trusted by internet marketers and influencers worldwide. Also featured in reviews and expert videos.</p>
<span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/TPL5HxdB1N0?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span>
<h3>👉 Grow and engage your email subscribers for FREE with Icegram Express</h3>
<p>Everything below is 100% free. No upsells. No surprises.</p>
<p><strong>Lead generation & list building</strong></p>
<ul>
<li>Smart opt-in forms: popup, inline, widget, shortcode, HTML</li>
<li>Unlimited lists tailored to your goals</li>
<li><a href="https://www.icegram.com/docs/category/icegram-express/data-stored-on-your-end#what-is-gdpr" rel="nofollow ugc">GDPR</a> ready: <a href="https://www.icegram.com/docs/category/icegram-express/opt-in-types" rel="nofollow ugc">single/double opt-in</a>, privacy checkbox</li>
<li>Unlimited Import/export via CSV</li>
</ul>
<p><strong>Campaigns & automation 🚀</strong></p>
<ul>
<li>Send newsletters, broadcasts, and auto post notification</li>
<li>Unlimited campaigns with open, click, and unsubscribe tracking</li>
<li>Auto-clean inactive subscribers (with engagement filters)</li>
</ul>
<p><strong>Email design & builder</strong></p>
<ul>
<li>Drag & drop builder + HTML editor</li>
<li>Responsive, professional templates for updates, offers, etc.</li>
<li>Personalization via dynamic content and shortcodes</li>
</ul>
<p><strong>Delivery control & flexibility</strong></p>
<ul>
<li>Use SMTP, <a href="https://wordpress.org/plugins/icegram-mailer/" rel="ugc">Icegram Mailer</a>, or any ESP (SendGrid, Amazon SES, etc.)</li>
<li>Throttle delivery speed to match server capacity</li>
<li>One click unsubscribe, Compliant with Gmail, Yahoo & GDPR</li>
</ul>
<p><strong>Integrations</strong></p>
<ul>
<li>Works with form plugins like CF7, WPForms, Gravity Forms and <a href="https://www.icegram.com/docs/category/icegram-express/create-workflow" rel="nofollow ugc">more</a></li>
<li>Native WordPress actions + WooCommerce-ready</li>
<li>Auto-convert commenters, users, and customers to subscribers</li>
</ul>
<p><strong>Reports & performance 📊</strong></p>
<ul>
<li>Campaign analytics: opens, clicks, unsubscribes</li>
<li>Track growth and engage</li>
</ul>
<p>Learn more on the <a href="https://www.icegram.com/express/?utm_source=ig_express_wp_readme&utm_medium=ig_express_featurespage_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">Icegram Express features page</a>.</p>
<h3>🔥Icegram Express Pro – Advanced Email Marketing & Automation</h3>
<p>Unlock powerful automation, targeting, and integrations for smarter campaigns and better results.🌟</p>
<p><strong>Advanced automation & scheduling</strong></p>
<ul>
<li>Autoresponders, <a href="https://www.icegram.com/sales-email-sequence/" rel="nofollow ugc">sequences</a>, welcome emails</li>
<li>Smart scheduling: post digests, timezone-based send, smart send-time optimization</li>
<li>WooCommerce triggers: cart recovery, order updates, promotions</li>
</ul>
<p><strong>Audience management & compliance ✅</strong></p>
<ul>
<li>Email validation, CAPTCHA, spam scoring, blacklist support</li>
<li>Unsubscribe tracking, <a href="https://www.icegram.com/docs/category/icegram-express-premium/engagement-score" rel="nofollow ugc">Score engagement</a>, list cleanup</li>
<li>Import WP users, WooCommerce customers, Mailchimp Subscribers directly</li>
<li>Convert commenters to subscribers automatically</li>
</ul>
<p><strong>Premium design & personalization</strong></p>
<ul>
<li>Pro templates with advanced styling tools</li>
<li>Deep personalization via custom fields and dynamic content</li>
<li>Spam scoring to boost inbox placement</li>
</ul>
<p><strong>Analytics & insights</strong></p>
<ul>
<li>Detailed campaign <a href="https://www.icegram.com/docs/category/icegram-express-premium/email-campaigns-analytics" rel="nofollow ugc">analytics & reporting</a></li>
<li>Exportable reports for offline sharing</li>
<li>Performance tracking for subscribers</li>
</ul>
<p><strong>Integrations & Dev tools 🛠️</strong></p>
<ul>
<li>REST API & Webhooks for external app workflows</li>
<li>Supports CF7, WPForms, Member plugins, LMS (like <a href="https://www.icegram.com/docs/category/icegram-express/learndash-lms-integration" rel="nofollow ugc">LearnDash</a>), WooCommerce</li>
<li><a href="https://www.icegram.com/docs/category/icegram-express-premium/third-party-email-sending-services/" rel="nofollow ugc">ESP integrations</a>: MailerSend, Mailgun, SendGrid, Sendinblue, Post SMTP</li>
</ul>
<p><strong>Security & team controls</strong></p>
<ul>
<li>Role-based access for team members</li>
<li>Activity logs and audit trails</li>
<li>Assured <a href="https://www.icegram.com/contact/" rel="nofollow ugc">priority support</a> for Pro users</li>
</ul>
<h3>🛍️ WooCommerce email marketing automation</h3>
<p>Icegram Express is a robust email marketing platform for WooCommerce.</p>
<p>➜ Send product promotions and offers (free)<br />
➜ Segment WooCommerce buyers for better targeting (free)<br />
➜ Send coupons and personalized deals (Pro)<br />
➜ Recover abandoned carts automatically (Pro)<br />
➜ Trigger emails on purchases, order changes, and more (Pro)<br />
➜ Win-back campaigns for inactive customers (Pro)</p>
<p>Grow your WooCommerce store with powerful marketing automation tools – convert more, drive repeat purchases, and increase LTV.</p>
<h3>✨ How others use Icegram Express</h3>
<p>➜ Bloggers & content creators: Engage readers with Email Newsletters, post notifications, and updates<br />
➜ eCommerce sellers: Automate promotions, seasonal campaigns, cart recovery, upsells using WooCommerce email marketing<br />
➜ Marketers & agencies: Run professional Email Campaigns, track results, and scale with workflow automations and segmentation</p>
<p>💯 100% worth it – I’ve tried a lot of different plugins for managing my subscriber list, but this one is by far the best. Great for professional bloggers! – <a href="https://wordpress.org/support/topic/great-for-professional-bloggers/" rel="ugc">rickvidallon</a></p>
<p>See how others succeed — explore some <a href="https://www.icegram.com/category/case-study/?utm_source=ig_express_wp_readme&utm_medium=casestudies_clickhere_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">case studies here</a>.</p>
<h3>Frequently Asked Questions</h3>
<p><strong>Q: Is Icegram Express suitable for beginners?</strong><br />
A: Absolutely! With an intuitive setup and a drag-and-drop editor, even non-tech users can create professional campaigns in minutes.</p>
<p><strong>Q: Why should I choose Icegram Express, and not other email marketing solutions?</strong><br />
A: If you want rock solid features, reliability and a product designed with your goals in mind, choose Icegram Express. If you want to spend a lot of money and confuse yourself – you can go with big name mail monkeys.</p>
<p><strong>Q: How does Icegram Express integrate with WooCommerce?</strong><br />
A: It offers robust WooCommerce email marketing features, including automated order notifications, cart recovery, and personalized product promotions.</p>
<p><strong>Q: What’s the difference between the free and Pro versions?</strong><br />
A: The free version provides complete email marketing essentials, while the Pro version unlocks advanced automation, dynamic content personalization, enhanced reporting, additional templates, and much more for power users.</p>
<h3>Other solutions from Icegram team</h3>
<ul>
<li><a href="https://wordpress.org/plugins/icegram/" rel="ugc">Icegram Engage</a> – popups, welcome bar, opt-ins, and lead generation plugin</li>
<li><a href="https://srd.wordpress.org/plugins/icegram-mailer/" rel="nofollow ugc">Icegram Mailer</a> – reliable email delivery service for WordPress & WooCommerce</li>
<li><a href="https://wordpress.org/plugins/icegram-rainmaker/" rel="ugc">Icegram Collect</a> – best lead gen forms plugin on WordPress</li>
<li><a href="https://wordpress.org/plugins/duplicate-post-page-copy-clone-wp/" rel="ugc">Post / Page Duplicate</a> – instantly duplicate pages, posts, or custom content</li>
<li><a href="https://wordpress.org/plugins/switch-user-login-by-icegram/" rel="ugc">Switch User Login by Icegram</a> – Easily switch between user accounts </li>
<li><a href="https://wordpress.org/plugins/icegram-cookie-manager/" rel="ugc">Icegram Cookie Manager</a> – Manage cookie consent and compliance for GDPR and privacy laws</li>
<li><a href="https://wordpress.org/plugins/temporary-login-without-password/" rel="ugc">Temporary Login Without Password</a> – share magic login links that work without password – great for giving access to your site to support teams or developers</li>
<li><a href="https://wordpress.org/plugins/smart-manager-for-wp-e-commerce/" rel="ugc">Smart Manager</a> – manage & bulk edit posts, users, WooCommerce products, orders & more..</li>
<li><a href="https://wordpress.org/plugins/offermative-discount-pricing-related-products-upsell-funnels-for-woocommerce/" rel="ugc">Offermative</a> – dynamic discount pricing, related product recommendations, upsells, and funnels for WooCommerce</li>
<li><a href="https://wordpress.org/plugins/woocommerce-putler-connector/" rel="ugc">Putler</a> – the best analytics for ecommerce – combines all your data in one place</li>
</ul>
<h3>💬 Need help? We’re just a click away!</h3>
<ul>
<li>New? Follow our comprehensive <a href="https://www.icegram.com/docs/category/icegram-express/getting-started/?utm_source=ig_express_wp_readme&utm_medium=installation_guide_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">installation guide</a></li>
<li>Explore our <a href="https://www.icegram.com/docs/category/icegram-express/?utm_source=ig_express_wp_readme&utm_medium=documentation_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">documentation</a> — your answer might already be there</li>
<li>On a premium plan? You get <a href="https://www.icegram.com/contact/?utm_source=ig_express_wp_readme&utm_medium=prioritysupport_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">priority support</a> via email or Facebook.</li>
<li>Know more about <a href="https://www.icegram.com/types-of-email-marketing/?utm_source=ig_express_wp_readme&utm_medium=typesof_emailcampaigns_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">different types of email campaigns</a> in this guide. Our <a href="https://www.icegram.com/blog/?utm_source=ig_express_wp_readme&utm_medium=blog_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">blog</a> has a lot of other useful guides too.</li>
<li>Checkout: <a href="https://www.icegram.com/express/pricing/?utm_source=ig_express_wp_readme&utm_medium=ig_express_premiumplans_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">Icegram Express premium plans</a> | <a href="https://www.icegram.com/blog/?utm_source=ig_express_wp_readme&utm_medium=marketingblog_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">Marketing Blog</a> | <a href="https://www.icegram.com/contact/?utm_source=ig_express_wp_readme&utm_medium=supporthelpdesk_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">Support Help Desk</a> | <a href="https://www.icegram.com/category/case-study/?utm_source=ig_express_wp_readme&utm_medium=casestudies_clickhere_anchor_text&utm_campaign=ig_express_wp_readme_traffic" rel="nofollow ugc">Case studies</a></li>
<li>Let’s socialize: <a href="https://www.facebook.com/groups/2298909487017349" rel="nofollow ugc">Private Facebook Group</a> | <a href="https://www.facebook.com/icegram/" rel="nofollow ugc">Facebook Page</a> | <a href="https://twitter.com/icegram" rel="nofollow ugc">Twitter Handle</a> | <a href="https://www.youtube.com/@icegramofficial" rel="nofollow ugc">YouTube channel</a></li>
</ul>