plugin

Icegram Vulnerabilities

39 known security issues reported for the Icegram WordPress plugin. Most recent disclosed Jul 31, 2026.

1 high 18 medium

Running Icegram on your site? Check whether your installed version is affected.

Scan your site free

Icegram Engage <= 3.1.42 - Authenticated (Contributor+) Second-Order SQL Injection via 'messages[][id]' Parameter

medium

The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via 'messages[][id]' Parameter in all versions up to, and including, 3.1.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL quer...

CVSS:
6.5
Affected:
up to 3.1.42
Fixed in:
3.1.43
Disclosed:
Jul 31, 2026

CVE-2026-16087 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] <= 3.1.35 (unfixed)

unknown

[en] Missing Authorization vulnerability in Icegram Icegram icegram allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Icegram: from n/a through <= 3.1.35.

Affected:
up to 3.1.35
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-68507 on NVD →

Icegram <= 3.1.35 - Missing Authorization

medium

The Icegram Engage – Popups, Optins, CTAs & lot more… plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.35. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.1.35
Fixed in:
3.1.36
Disclosed:
Jan 5, 2026

CVE-2025-68507 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.32

unknown

[en] The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.1.32
Fixed in:
3.1.32
Disclosed:
May 15, 2025

CVE-2024-13486 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.32

unknown

[en] The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 3.1.32
Fixed in:
3.1.32
Disclosed:
May 15, 2025

CVE-2024-13482 on NVD →

Icegram Engage <= 3.1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

CVSS:
4.4
Affected:
up to 3.1.31
Fixed in:
3.1.32
Disclosed:
Mar 3, 2025

CVE-2024-13482 on NVD →

Icegram Engage <= 3.1.31 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

CVSS:
4.4
Affected:
up to 3.1.31
Fixed in:
3.1.32
Disclosed:
Mar 3, 2025

CVE-2024-13486 on NVD →

Icegram <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 3.1.31
Fixed in:
3.1.32
Disclosed:
Jan 24, 2025

CVE-2025-24542 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.32

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icegram Icegram allows Stored XSS. This issue affects Icegram: from n/a through 3.1.31.

Affected:
up to 3.1.32
Fixed in:
3.1.32
Disclosed:
Jan 24, 2025

CVE-2025-24542 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.32

unknown

[en] The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 3.1.32
Fixed in:
3.1.32
Disclosed:
Jan 6, 2025

CVE-2024-12302 on NVD →

Icegram Engage <= 3.1.31 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac...

CVSS:
6.4
Affected:
up to 3.1.31
Fixed in:
3.1.32
Disclosed:
Dec 16, 2024

CVE-2024-12302 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.25

unknown

[en] Missing Authorization vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Nov 1, 2024

CVE-2024-39625 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.25

unknown

[en] Missing Authentication for Critical Function vulnerability in icegram Icegram allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Icegram: from n/a through 3.1.24.

Affected:
up to 3.1.25
Fixed in:
3.1.25
Disclosed:
Aug 19, 2024

CVE-2024-43272 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.26

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Icegram allows Stored XSS.This issue affects Icegram: from n/a through 3.1.25.

Affected:
up to 3.1.26
Fixed in:
3.1.26
Disclosed:
Aug 18, 2024

CVE-2024-43344 on NVD →

Icegram <= 3.1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
6.4
Affected:
up to 3.1.25
Fixed in:
3.1.26
Disclosed:
Aug 16, 2024

CVE-2024-43344 on NVD →

Icegram <= 3.1.24 - Missing Authorization

medium

The Icegram plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the display_messages() function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to preview campaigns

CVSS:
5.3
Affected:
up to 3.1.24
Fixed in:
3.1.25
Disclosed:
Aug 12, 2024

CVE-2024-43272 on NVD →

Icegram <= 3.1.24 - Missing Authorization to Unauthenticated Message Duplication

medium

The Icegram plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_message() function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to duplicate messages.

CVSS:
5.3
Affected:
up to 3.1.24
Fixed in:
3.1.25
Disclosed:
Jul 22, 2024

CVE-2024-39625 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.22

unknown

[en] Missing Authorization vulnerability in Icegram.This issue affects Icegram: from n/a through 3.1.21.

Affected:
up to 3.1.22
Fixed in:
3.1.22
Disclosed:
Jun 8, 2024

CVE-2024-21748 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.20

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building allows Stored XSS.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins an...

Affected:
up to 3.1.20
Fixed in:
3.1.20
Disclosed:
Feb 1, 2024

CVE-2023-51532 on NVD →

Icegram <= 3.1.21 - Missing Authorization

medium

The Icegram plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.21. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.1.21
Fixed in:
3.1.22
Disclosed:
Jan 5, 2024

CVE-2024-21748 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.19

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Icegram Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building.This issue affects Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building: from n/a through 3.1.18.

Affected:
up to 3.1.19
Fixed in:
3.1.19
Disclosed:
Jan 5, 2024

CVE-2023-52119 on NVD →

Icegram <= 3.1.18 - Cross-Site Request Forgery via save_campaign_preview

medium

The Icegram plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.18. This is due to missing or incorrect nonce validation on the save_campaign_preview() function. This makes it possible for unauthenticated attackers to save campaign previews via a forged request granted...

CVSS:
4.3
Affected:
up to 3.1.18
Fixed in:
3.1.19
Disclosed:
Dec 28, 2023

CVE-2023-52119 on NVD →

Icegram <= 3.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via Campaign Message

medium

The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the campaign message field in versions up to, and including, 3.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...

CVSS:
6.4
Affected:
up to 3.1.19
Fixed in:
3.1.20
Disclosed:
Dec 27, 2023

CVE-2023-51532 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 3.1.12

unknown

[en] The Icegram Engage WordPress plugin before 3.1.12 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Affected:
up to 3.1.12
Fixed in:
3.1.12
Disclosed:
Jun 12, 2023

CVE-2023-2398 on NVD →

Icegram Engage <= 3.1.11 - Reflected Cross-Site Scripting

medium

The Icegram Engage plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 3.1.11
Fixed in:
3.1.12
Disclosed:
May 22, 2023

CVE-2023-2398 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 2.1.8

unknown

[en] The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
Jun 27, 2022

CVE-2022-1776 on NVD →

Icegram Engage <= 2.1.7 - Cross-Site Scripting

medium

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVSS:
6.1
Affected:
up to 2.1.8
Fixed in:
2.1.8
Disclosed:
May 30, 2022

CVE-2022-1776 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 2.0.5

unknown

[en] The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Dec 21, 2021

CVE-2021-24941 on NVD →

Icegram <= 2.0.4 - Reflected Cross-Site Scripting via message_id

medium

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitize and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Nov 22, 2021

CVE-2021-24941 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 2.0.3

unknown

[en] WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Oct 19, 2021

CVE-2021-36832 on NVD →

Icegram <= 2.0.2 - Authenticated Stored Cross-Site Scripting

medium

WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.

CVSS:
4.8
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Aug 17, 2021

CVE-2021-36832 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 1.9.19

unknown

[en] The icegram plugin before 1.9.19 for WordPress has XSS.

Affected:
up to 1.9.19
Fixed in:
1.9.19
Disclosed:
Sep 16, 2019

CVE-2016-10963 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 1.9.19

unknown

[en] The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

Affected:
up to 1.9.19
Fixed in:
1.9.19
Disclosed:
Sep 16, 2019

CVE-2016-10962 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 1.10.29

unknown

[en] The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

Affected:
up to 1.10.29
Fixed in:
1.10.29
Disclosed:
Aug 30, 2019

CVE-2019-15830 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 1.10.29

unknown

Cross-Site Request Forgery (CSRF) to Stored XSS vulnerabilities found in WordPress Icegram plugin (version <= 1.10.28.2).

Affected:
up to 1.10.29
Fixed in:
1.10.29
Disclosed:
Jul 10, 2019

Icegram <= 1.10.28.2 - Cross-Site Scripting

medium

The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.

CVSS:
6.4
Affected:
up to 1.10.28.2
Fixed in:
1.10.29
Disclosed:
Jul 9, 2019

CVE-2019-15830 on NVD →

Icegram <= 1.9.18 - Cross-Site Request Forgery

high

The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

CVSS:
8.8
Affected:
up to 1.9.19
Fixed in:
1.9.19
Disclosed:
Jul 19, 2016

CVE-2016-10962 on NVD →

Icegram <= 1.9.18 - Cross-Site Scripting

medium

The icegram plugin before 1.9.19 for WordPress has XSS in 'message' parameter.

CVSS:
6.1
Affected:
up to 1.9.19
Fixed in:
1.9.19
Disclosed:
Jul 19, 2016

CVE-2016-10963 on NVD →

Icegram Engage &#8211; Popups, Optins, CTAs &amp; lot more&#8230; [icegram] < 1.9.19

unknown

This vulnerability allows an attacker to overwrite any WordPress option with the value true. Upgrade this plugin.

Affected:
up to 1.9.19
Fixed in:
1.9.19
Disclosed:
Jul 19, 2016

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database