Impact
The vulnerability lies in the Icegram Express WordPress plugin before version 5.8.6, which fails to escape a list description setting before inserting it into an HTML attribute. This flaw can be used by any user with Administrator privileges or higher to inject arbitrary JavaScript that is stored in the database and executed when other users view the page. The flaw is a classic stored XSS, classified under CWE‑79, which could compromise the integrity of the affected site and expose administrative sessions to theft or manipulation.
Affected Systems
Any WordPress installation running Icegram Express prior to version 5.8.6 is affected. The vendor is listed as Unknown:Icegram Express, and all administrators and users above that role with access to the plugin settings are at risk.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity flaw, and the EPSS score is not available. Consequently, this vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to already have Administrator privileges or higher, or to fool an administrator into interacting with the vulnerable input. Because of this requirement, the exploit probability is modest, but the impact on an admin‑level user remains significant.
OpenCVE Enrichment