CVE-2026-97284: WordPress Icegram plugin <= 3.1.31 - PHP Object Injection vulnerability
Published Oct 1, 2026
·Updated
Contributor PHP Object Injection in Icegram <= 3.1.31 versions.
Affected Software
1 affected component
Icegram Icegram WordPress plugin<=3.1.31
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Icegram pluginto a version that resolves this vulnerability.Fixed in 3.1.44
Event History
Oct 1, 2026
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs low-level privileges, specifically Contributor access. The CVSS vector indicates that no user interaction is required.
2
Can this be exploited over the network?
Yes. The network attack vector and low attack complexity indicate that an authenticated Contributor could attempt exploitation remotely.
3
What is the potential impact if exploitation succeeds?
The CVSS assessment indicates high potential impact to confidentiality, integrity, and availability.