The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 1,826 live websites that are affected by CVE-2024-13482.
| Product | |
| Category | Lead Generation |
| Vulnerable Domains | 1,826 live websites (43% of Icegram install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 117 versions ( 97% of all versions) |
| 710 websites | |
| 118 websites | |
| 110 websites | |
| 102 websites | |
| 62 websites | |
| 52 websites | |
| 50 websites | |
| 45 websites | |
| 35 websites | |
| 34 websites |
| .com | 890 websites |
| .org | 78 websites |
| .it | 66 websites |
| .es | 50 websites |
| .de | 49 websites |
| .net | 47 websites |
| .fr | 45 websites |
| .pl | 40 websites |
| .co.uk | 39 websites |
| .nl | 32 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | **,*** | ||
| ******.**.id | ***,*** | ||
| **************.it | ***,*** | ||
| ***********.com | ***,*** | ||
| ******.com | ***,*** | ||
| *********.com | ***,*** | ||
| ********.es | ***,*** | ||
| *****.fr | ***,*** | ||
| ************.org | ***,*** | ||
| ************.***.hk | ***,*** |
FAQ