ZeroHour

CVE-2024-12302

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p29
Published
()
Modified
Description

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks

Vendors
icegram
Products
icegram engage
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.