CVE-2021-36832: WordPress Icegram plugin <= 2.0.2 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
Published Oct 19, 2021
·Updated
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&messagedata[16][headline]) input.
Affected Software
2 affected components
Icegram Icegram Wordpress<=2.0.2
Icegram Icegram Engage WordPress<=2.0.2
Remediation
Information
Update to 2.0.3 or higher version.
Event History
Oct 19, 2021
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36832?
CVE-2021-36832 has a high severity rating due to its potential for authenticated stored cross-site scripting (XSS).
2
How do I fix CVE-2021-36832?
To fix CVE-2021-36832, update the Icegram plugin to version 2.0.3 or later.
3
What versions are affected by CVE-2021-36832?
CVE-2021-36832 affects Icegram versions up to and including 2.0.2.
4
What type of vulnerability is CVE-2021-36832?
CVE-2021-36832 is classified as an authenticated stored cross-site scripting (XSS) vulnerability.
5
Is CVE-2021-36832 easily exploitable?
Yes, CVE-2021-36832 is easily exploitable if attackers gain authenticated access to the affected plugin.