CVE-2025-24587
moderateBlind SQL Injection in WordPress Email Subscription Popup Plugin (<= 1.2.23)
CVE-2025-24587 is a blind SQL injection flaw (CWE-89) in the Email Subscription Popup WordPress plugin (slug: email-subscribe), affecting all versions through 1.2.23. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:C) indicates the flaw is reachable over the network by a highly privileged account, such as an administrator, with no user interaction required, and crafted input is improperly neutralized when passed into a SQL query. Because the injection is blind, an attacker cannot see direct query output but can infer and extract database contents, giving high confidentiality impact per the CVSS score, with a low availability impact and a scope change suggesting effects beyond the vulnerable component. Any WordPress site running Email Subscription Popup version 1.2.23 or earlier is affected. There is no known public proof-of-concept and the flaw is not in CISA KEV, but its EPSS of 32.2% (98th percentile) indicates a meaningfully elevated probability of exploitation within the next 30 days.
What to do: Update the Email Subscription Popup plugin to the latest available release (any version newer than 1.2.23; verify the patched version on the plugin's WordPress.org page). Until patched, limit administrator-level accounts on affected sites, since the CVSS indicates exploitation requires high privileges, and consider web application firewall SQL-injection rules. Review admin accounts and logs for signs of unusual database activity or unauthorized subscription-related requests.
| Nks Email Subscription Popup (WordPress plugin, slug: email-subscribe) | all versions through <= 1.2.23 (no fixed version stated in the supplied data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nks Email Subscription Popup email-subscribe allows Blind SQL Injection.This issue affects Email Subscription Popup: from n/a through <= 1.2.23.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.