ZeroHour

CVE-2025-24587

moderate

Blind SQL Injection in WordPress Email Subscription Popup Plugin (<= 1.2.23)

CVSS 3.1
7.6 high
EPSS
32%p98
Published
()
Modified
AI analysis

CVE-2025-24587 is a blind SQL injection flaw (CWE-89) in the Email Subscription Popup WordPress plugin (slug: email-subscribe), affecting all versions through 1.2.23. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:C) indicates the flaw is reachable over the network by a highly privileged account, such as an administrator, with no user interaction required, and crafted input is improperly neutralized when passed into a SQL query. Because the injection is blind, an attacker cannot see direct query output but can infer and extract database contents, giving high confidentiality impact per the CVSS score, with a low availability impact and a scope change suggesting effects beyond the vulnerable component. Any WordPress site running Email Subscription Popup version 1.2.23 or earlier is affected. There is no known public proof-of-concept and the flaw is not in CISA KEV, but its EPSS of 32.2% (98th percentile) indicates a meaningfully elevated probability of exploitation within the next 30 days.

What to do: Update the Email Subscription Popup plugin to the latest available release (any version newer than 1.2.23; verify the patched version on the plugin's WordPress.org page). Until patched, limit administrator-level accounts on affected sites, since the CVSS indicates exploitation requires high privileges, and consider web application firewall SQL-injection rules. Review admin accounts and logs for signs of unusual database activity or unauthorized subscription-related requests.

Affected
Nks Email Subscription Popup (WordPress plugin, slug: email-subscribe)all versions through <= 1.2.23 (no fixed version stated in the supplied data)
Estimated exposure
moderateon the order of ~10,000 sites (low-adoption WordPress plugin; exact active-install count not in the supplied data) — Order-of-magnitude estimate based on this plugin's small adoption profile on the WordPress.org plugin directory, treated as low confidence because no authoritative active-install count was provided in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nks Email Subscription Popup email-subscribe allows Blind SQL Injection.This issue affects Email Subscription Popup: from n/a through <= 1.2.23.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.