Extension WordPress
Vulnérabilités Icegram Engage – Popups, Optins, CTAs & Lead Generation
Cette page rassemble les failles publiées pour Icegram Engage – Popups, Optins, CTAs & Lead Generation, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Icegram Engage – Popups, Optins, CTAs & Lead Generation
18 fiches
Icegram <= 3.1.35 – Missing Authorization
The Icegram Engage – Popups, Optins, CTAs & lot more… plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.1.35. This makes it…
*-3.1.35
3.1.36
05/01/2026
Icegram Engage <= 3.1.31 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization…
*-3.1.31
3.1.32
03/03/2025
Icegram Engage <= 3.1.31 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization…
*-3.1.31
3.1.32
03/03/2025
Icegram <= 3.1.31 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.1.31
3.1.32
24/01/2025
Icegram Engage <= 3.1.31 – Authenticated (Author+) Stored Cross-Site Scripting
The Icegram Engage – Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign settings in all versions up to, and including, 3.1.31 due to insufficient input sanitization…
*-3.1.31
3.1.32
16/12/2024
Icegram <= 3.1.25 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.1.25
3.1.26
16/08/2024
Icegram <= 3.1.24 – Missing Authorization
The Icegram plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the display_messages() function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to preview…
*-3.1.24
3.1.25
12/08/2024
Icegram <= 3.1.24 – Missing Authorization to Unauthenticated Message Duplication
The Icegram plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_message() function in versions up to, and including, 3.1.24. This makes it possible for unauthenticated attackers to duplicate…
*-3.1.24
3.1.25
22/07/2024
Icegram <= 3.1.21 – Missing Authorization
The Icegram plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.1.21. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-3.1.21
3.1.22
05/01/2024
Icegram <= 3.1.18 – Cross-Site Request Forgery via save_campaign_preview
The Icegram plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.18. This is due to missing or incorrect nonce validation on the save_campaign_preview() function. This makes it possible for unauthenticated attackers…
*-3.1.18
3.1.19
28/12/2023
Icegram <= 3.1.19 – Authenticated (Contributor+) Stored Cross-Site Scripting via Campaign Message
The Icegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the campaign message field in versions up to, and including, 3.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-3.1.19
3.1.20
27/12/2023
Icegram Engage <= 3.1.11 – Reflected Cross-Site Scripting
The Icegram Engage plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-3.1.11
3.1.12
22/05/2023
Icegram Engage <= 2.1.7 – Cross-Site Scripting
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
[*, 2.1.8)
2.1.8
30/05/2022
Icegram <= 2.0.4 – Reflected Cross-Site Scripting via message_id
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitize and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site…
[*, 2.0.5)
2.0.5
22/11/2021
Icegram <= 2.0.2 – Authenticated Stored Cross-Site Scripting
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions
*-2.0.2
2.0.3
17/08/2021
Icegram <= 1.10.28.2 – Cross-Site Scripting
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
*-1.10.28.2
1.10.29
09/07/2019
Icegram <= 1.9.18 – Cross-Site Scripting
The icegram plugin before 1.9.19 for WordPress has XSS in 'message' parameter.
[*, 1.9.19)
1.9.19
19/07/2016
Icegram <= 1.9.18 – Cross-Site Request Forgery
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
[*, 1.9.19)
1.9.19
19/07/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.