CVE-2024-13486: Icegram Engage < 3.1.32 - Admin+ Stored XSS
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13486?
CVE-2024-13486 is classified as a high severity vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-13486?
You can fix CVE-2024-13486 by updating the Icegram Engage WordPress plugin to version 3.1.32 or later.
Who is affected by CVE-2024-13486?
CVE-2024-13486 affects users of the Icegram Engage WordPress plugin prior to version 3.1.32.
What type of vulnerability is CVE-2024-13486?
CVE-2024-13486 is a Stored Cross-Site Scripting vulnerability that can be exploited by high privilege users.
What systems are vulnerable to CVE-2024-13486?
Any WordPress site using the Icegram Engage plugin versions before 3.1.32 is vulnerable to CVE-2024-13486.