CVE-2019-15830: Icegram Engage

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

Affected products

  • Icegram Icegram Engage: before 1.10.29 (fixed in 1.10.29)

Published 2019-08-30. Last modified 2026-06-17.