CVE-2025-24542: WordPress Icegram Engage plugin <= 3.1.31 - Cross Site Scripting (XSS) vulnerability
Published Jan 24, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram icegram allows Stored XSS.This issue affects Icegram: from n/a through <= 3.1.31.
Affected Software
1 affected component
Icegram Icegram (WordPress plugin)<=3.1.31
Remediation
Information
Update the WordPress Icegram wordpress plugin to the latest available version (at least 3.1.32).
Event History
Jan 24, 2025
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24542?
CVE-2025-24542 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS).
2
How do I fix CVE-2025-24542?
To fix CVE-2025-24542, upgrade Icegram to the latest version beyond 3.1.31.
3
What versions of Icegram are affected by CVE-2025-24542?
CVE-2025-24542 affects Icegram versions prior to 3.1.31.
4
What kind of attacks can be executed using CVE-2025-24542?
CVE-2025-24542 can be exploited to execute stored XSS attacks, allowing an attacker to inject malicious scripts.
5
Is CVE-2025-24542 specific to any products?
Yes, CVE-2025-24542 specifically affects Icegram and Icegram Engage plugins.