Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Injection via 'messages[][id]' Parameter
medium
The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via 'messages[][id]' Parameter in all versions up to, and including, 3.1.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL quer...
- CVSS:
- 6.5
- Affected:
- up to 3.1.42
- Fixed in:
- 3.1.43
- Disclosed:
- Jul 31, 2026
CVE-2026-16087 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] <= 3.1.35 (unfixed)
unknown
[en] Missing Authorization vulnerability in Icegram Icegram icegram allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Icegram: from n/a through <= 3.1.35.
- Affected:
- up to 3.1.35
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-68507 on NVD →
Icegram <= 3.1.35 - Missing Authorization
medium
The Icegram Engage – Popups, Optins, CTAs & lot more… plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.35. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.1.35
- Fixed in:
- 3.1.36
- Disclosed:
- Jan 5, 2026
CVE-2025-68507 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.32
unknown
[en] The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.1.32
- Fixed in:
- 3.1.32
- Disclosed:
- May 15, 2025
CVE-2024-13486 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.32
unknown
[en] The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.1.32
- Fixed in:
- 3.1.32
- Disclosed:
- May 15, 2025
CVE-2024-13482 on NVD →
Icegram Engage <= 3.1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- CVSS:
- 4.4
- Affected:
- up to 3.1.31
- Fixed in:
- 3.1.32
- Disclosed:
- Mar 3, 2025
CVE-2024-13482 on NVD →
Icegram Engage <= 3.1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- CVSS:
- 4.4
- Affected:
- up to 3.1.31
- Fixed in:
- 3.1.32
- Disclosed:
- Mar 3, 2025
CVE-2024-13486 on NVD →
Icegram <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 3.1.31
- Fixed in:
- 3.1.32
- Disclosed:
- Jan 24, 2025
CVE-2025-24542 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.32
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icegram Icegram allows Stored XSS. This issue affects Icegram: from n/a through 3.1.31.
- Affected:
- up to 3.1.32
- Fixed in:
- 3.1.32
- Disclosed:
- Jan 24, 2025
CVE-2025-24542 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.32
unknown
[en] The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.1.32
- Fixed in:
- 3.1.32
- Disclosed:
- Jan 6, 2025
CVE-2024-12302 on NVD →
Icegram Engage <= 3.1.31 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 3.1.31
- Fixed in:
- 3.1.32
- Disclosed:
- Dec 16, 2024
CVE-2024-12302 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.25
unknown
[en] Missing Authorization vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.25
- Disclosed:
- Nov 1, 2024
CVE-2024-39625 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.25
unknown
[en] Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.25
- Disclosed:
- Aug 19, 2024
CVE-2024-43272 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.26
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Icegram allows Stored XSS.This issue affects Icegram: from n/a through 3.1.25.
- Affected:
- up to 3.1.26
- Fixed in:
- 3.1.26
- Disclosed:
- Aug 18, 2024
CVE-2024-43344 on NVD →
Icegram <= 3.1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 3.1.25
- Fixed in:
- 3.1.26
- Disclosed:
- Aug 16, 2024
CVE-2024-43344 on NVD →
Icegram <= 3.1.24 - Missing Authorization
medium
The Icegram plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the display_messages() function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to preview campaigns
- CVSS:
- 5.3
- Affected:
- up to 3.1.24
- Fixed in:
- 3.1.25
- Disclosed:
- Aug 12, 2024
CVE-2024-43272 on NVD →
Icegram <= 3.1.24 - Missing Authorization to Unauthenticated Message Duplication
medium
The Icegram plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_message() function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to duplicate messages.
- CVSS:
- 5.3
- Affected:
- up to 3.1.24
- Fixed in:
- 3.1.25
- Disclosed:
- Jul 22, 2024
CVE-2024-39625 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.22
unknown
[en] Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.
- Affected:
- up to 3.1.22
- Fixed in:
- 3.1.22
- Disclosed:
- Jun 8, 2024
CVE-2024-21748 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.20
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins an...
- Affected:
- up to 3.1.20
- Fixed in:
- 3.1.20
- Disclosed:
- Feb 1, 2024
CVE-2023-51532 on NVD →
Icegram <= 3.1.21 - Missing Authorization
medium
The Icegram plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.21. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 3.1.21
- Fixed in:
- 3.1.22
- Disclosed:
- Jan 5, 2024
CVE-2024-21748 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.19
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.18.
- Affected:
- up to 3.1.19
- Fixed in:
- 3.1.19
- Disclosed:
- Jan 5, 2024
CVE-2023-52119 on NVD →
Icegram <= 3.1.18 - Cross-Site Request Forgery via save_campaign_preview
medium
The Icegram plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.18. This is due to missing or incorrect nonce validation on the save_campaign_preview() function. This makes it possible for unauthenticated attackers to save campaign previews via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 3.1.18
- Fixed in:
- 3.1.19
- Disclosed:
- Dec 28, 2023
CVE-2023-52119 on NVD →
Icegram <= 3.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Campaign Message
medium
The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the campaign message field in versions up to, and including, 3.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 3.1.19
- Fixed in:
- 3.1.20
- Disclosed:
- Dec 27, 2023
CVE-2023-51532 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 3.1.12
unknown
[en] The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 3.1.12
- Fixed in:
- 3.1.12
- Disclosed:
- Jun 12, 2023
CVE-2023-2398 on NVD →
Icegram Engage <= 3.1.11 - Reflected Cross-Site Scripting
medium
The Icegram Engage plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 3.1.11
- Fixed in:
- 3.1.12
- Disclosed:
- May 22, 2023
CVE-2023-2398 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 2.1.8
unknown
[en] The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.8
- Disclosed:
- Jun 27, 2022
CVE-2022-1776 on NVD →
Icegram Engage <= 2.1.7 - Cross-Site Scripting
medium
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
- CVSS:
- 6.1
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.8
- Disclosed:
- May 30, 2022
CVE-2022-1776 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 2.0.5
unknown
[en] The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Dec 21, 2021
CVE-2021-24941 on NVD →
Icegram <= 2.0.4 - Reflected Cross-Site Scripting via message_id
medium
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitize and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Nov 22, 2021
CVE-2021-24941 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 2.0.3
unknown
[en] WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Oct 19, 2021
CVE-2021-36832 on NVD →
Icegram <= 2.0.2 - Authenticated Stored Cross-Site Scripting
medium
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
- CVSS:
- 4.8
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Aug 17, 2021
CVE-2021-36832 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 1.9.19
unknown
[en] The icegram plugin before 1.9.19 for WordPress has XSS.
- Affected:
- up to 1.9.19
- Fixed in:
- 1.9.19
- Disclosed:
- Sep 16, 2019
CVE-2016-10963 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 1.9.19
unknown
[en] The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
- Affected:
- up to 1.9.19
- Fixed in:
- 1.9.19
- Disclosed:
- Sep 16, 2019
CVE-2016-10962 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 1.10.29
unknown
[en] The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
- Affected:
- up to 1.10.29
- Fixed in:
- 1.10.29
- Disclosed:
- Aug 30, 2019
CVE-2019-15830 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 1.10.29
unknown
Cross-Site Request Forgery (CSRF) to Stored XSS vulnerabilities found in WordPress Icegram plugin (version <= 1.10.28.2).
- Affected:
- up to 1.10.29
- Fixed in:
- 1.10.29
- Disclosed:
- Jul 10, 2019
Icegram <= 1.10.28.2 - Cross-Site Scripting
medium
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
- CVSS:
- 6.4
- Affected:
- up to 1.10.28.2
- Fixed in:
- 1.10.29
- Disclosed:
- Jul 9, 2019
CVE-2019-15830 on NVD →
Icegram <= 1.9.18 - Cross-Site Request Forgery
high
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
- CVSS:
- 8.8
- Affected:
- up to 1.9.19
- Fixed in:
- 1.9.19
- Disclosed:
- Jul 19, 2016
CVE-2016-10962 on NVD →
Icegram <= 1.9.18 - Cross-Site Scripting
medium
The icegram plugin before 1.9.19 for WordPress has XSS in 'message' parameter.
- CVSS:
- 6.1
- Affected:
- up to 1.9.19
- Fixed in:
- 1.9.19
- Disclosed:
- Jul 19, 2016
CVE-2016-10963 on NVD →
Icegram Engage – Popups, Optins, CTAs & lot more… [icegram] < 1.9.19
unknown
This vulnerability allows an attacker to overwrite any WordPress option with the value true.
Upgrade this plugin.
- Affected:
- up to 1.9.19
- Fixed in:
- 1.9.19
- Disclosed:
- Jul 19, 2016