CVE-2024-12302: Icegram Engage < 3.1.32 - Author+ Stored XSS
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12302?
CVE-2024-12302 has been assessed as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-12302?
To fix CVE-2024-12302, update the Icegram Engage plugin to version 3.1.32 or later, which includes the necessary security patches.
Who is affected by CVE-2024-12302?
CVE-2024-12302 affects users of the Icegram Engage WordPress plugin versions prior to 3.1.32.
What kind of attack can be executed due to CVE-2024-12302?
CVE-2024-12302 can allow attackers to execute Stored Cross-Site Scripting (XSS) attacks.
What are the consequences of CVE-2024-12302 being exploited?
Exploitation of CVE-2024-12302 could lead to the execution of malicious scripts in the user's browser, potentially compromising user data.