Impact
An unauthenticated XSS vulnerability allows an attacker to inject arbitrary client‑side scripts into web pages served by the plugin. While the flaw does not disclose server‑side data directly, the injected code runs in the browser context of any visitor, potentially leading to cookie theft, session hijacking, defacement, or the delivery of malicious payloads. The weakness lies in the lack of proper output encoding or sanitization when rendering user‑controlled content.
Affected Systems
WordPress sites running the Icegram Email Subscribers & Newsletters plugin version 5.9.33 or earlier are impacted. No additional vendor or version details beyond the listed product are provided.
Risk and Exploitability
The common vulnerability scoring system assigns a score of 7.1, indicating a high severity. The EPSS metric is not available, so the current probability of exploitation is unknown from that source. The vulnerability is not present in the CISA KEV catalog. Because the bug is unauthenticated, any user who can submit input to the plugin can trigger the exploit, and the payload executes in the victim’s browser, making the attack vector broad but not requiring privileged access.
OpenCVE Enrichment