cleantalk
Vulnerabilities and Security Researches

Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building, CVE-2024-12302

CVE, Research URL

CVE-2024-12302

Published on
Jan 06, 2025
Research Description
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks
Affected versions
max 3.1.32.
Status
vulnerable