CVE-2025-15692: Icegram Express < 5.8.6 - Admin+ Stored XSS
Published Sep 2, 2026
·Updated
The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Icegram Express Icegram Express WordPress plugin<5.8.6
Event History
Sep 2, 2026
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a WordPress account with the Administrator role or higher. The vulnerable setting is a list description field in the Icegram Express plugin.
2
What versions are affected?
Icegram Express versions before 5.8.6 are affected. Updating to version 5.8.6 or later addresses the issue.
3
What is the impact of successful exploitation?
A privileged user can store malicious script content that is later output in an HTML attribute. The reported impact is limited to confidentiality and integrity, with no availability impact indicated.