CVE-2023-51532: WordPress Icegram Plugin <= 3.1.19 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.19.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51532?
CVE-2023-51532 has been classified as a medium severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2023-51532?
To fix CVE-2023-51532, update the Icegram Engage plugin to the latest version beyond 3.1.19.
What type of vulnerability is CVE-2023-51532?
CVE-2023-51532 is classified as a Cross-site Scripting (XSS) vulnerability.
Which software is affected by CVE-2023-51532?
CVE-2023-51532 affects Icegram Engage plugin versions up to and including 3.1.19.
Can CVE-2023-51532 lead to data theft?
Yes, CVE-2023-51532 can potentially lead to data theft through unauthorized access and execution of scripts.