cleantalk
Vulnerabilities and Security Researches

Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building, CVE-2023-2398

CVE, Research URL

CVE-2023-2398

Published on
Jun 12, 2023
Research Description
The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
max 3.1.12.
Status
vulnerable