CVE-2024-13482: Icegram Engage < 3.1.32 - Admin+ Stored XSS
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13482?
CVE-2024-13482 has a severity rating that indicates a significant risk of stored cross-site scripting (XSS) attacks affecting high privilege users.
How do I fix CVE-2024-13482?
To fix CVE-2024-13482, update the Icegram Engage plugin to version 3.1.32 or later where this vulnerability is addressed.
Who is affected by CVE-2024-13482?
CVE-2024-13482 affects users of the Icegram Engage plugin versions prior to 3.1.32, especially those with high privilege roles such as administrators.
What kind of attacks can CVE-2024-13482 enable?
CVE-2024-13482 can enable stored cross-site scripting (XSS) attacks, allowing malicious scripts to be executed in the context of the victim's browser session.
What is the nature of the vulnerability in CVE-2024-13482?
CVE-2024-13482 is caused by insufficient sanitization and escaping of settings within the Icegram Engage plugin, which can be exploited by high privilege users.