Impact
Icegram Engage allows an attacker to embed malicious scripting code that is permanently stored in the site. When visitors load a page that displays the stored content, the code executes in their browsers, potentially enabling cookie theft, credential hijacking, or defacement of the web page. The attack exploits the plugin’s failure to neutralize input during web page generation.
Affected Systems
WordPress sites that use the Icegram Engage plugin version 3.1.31 or earlier are affected. No other vendors or products are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating a moderate severity. The EPSS score is less than 1%, implying a low probability of exploitation at the time of this analysis. It is not listed in CISA’s KEV catalog. Attackers would likely target the plugin’s data entry interface where unfiltered input is accepted; the vector is inbound web traffic to the WordPress site. Because the flaw results in a stored payload, any user who views the affected content can be impacted.
OpenCVE Enrichment
EUVD