CVE-2023-25024: WordPress Icegram Collect plugin <= 1.3.8 is vulnerable to Cross Site Scripting (XSS)
Published Apr 7, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Icegram Icegram Collect plugin <= 1.3.8 versions.
Affected Software
1 affected component
Icegram Icegram Collect Wordpress<=1.3.8
Remediation
Information
Update to 1.3.9 or a higher version.
Event History
Apr 7, 2023
CVE Published
via MITRE·10:51 AM
Data Sourced
via MITRE·10:51 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-25024.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Icegram Icegram Collect plugin <= 1.3.8 versions.'
3
What is the severity of CVE-2023-25024?
The severity of CVE-2023-25024 is medium with a severity value of 4.8.
4
Which software versions are affected by CVE-2023-25024?
The Icegram Icegram Collect plugin versions up to and including 1.3.8 are affected by CVE-2023-25024.
5
How can I fix CVE-2023-25024?
To fix CVE-2023-25024, make sure to update the Icegram Icegram Collect plugin to a version higher than 1.3.8.