Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building, CVE-2022-1776
- CVE, Research URL
- Home page URL
- Application
-
Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building
- Published on
- Jun 27, 2022
- Research Description
- The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
- Affected versions
-
max 2.1.8.
- Status
-
vulnerable