CVE-2024-12302: Icegram Engage
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks
Affected products
- Icegram Icegram Engage: before 3.1.32 (fixed in 3.1.32)
Published 2025-01-06. Last modified 2026-06-17.