Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building, CVE-2023-2398
- CVE, Research URL
- Home page URL
- Application
-
Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building
- Published on
- Jun 12, 2023
- Research Description
- The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected versions
-
max 3.1.12.
- Status
-
vulnerable