CVE-2024-13482

Icegram Engage < 3.1.32 - Admin+ Stored XSS

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 1,826 live websites that are affected by CVE-2024-13482.

Run a Free Instant Scan




Affected Software

Product  Icegram
Category Lead Generation
Vulnerable Domains1,826 live websites (43% of Icegram install base)
Vulnerable Versions
  • from 0 through 3.1.32
Vulnerable Versions Count117 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-287 Improper Authentication



Details

  • Published - May 15, 2025
  • Updated - May 20, 2025

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-13482
United States710 websites



France118 websites
Germany110 websites
Italy102 websites
Spain62 websites
Poland52 websites
GB50 websites
Netherlands45 websites
Australia35 websites
Romania34 websites

Website Distribution by TLD

Number of websites using CVE-2024-13482
.com890 websites
.org78 websites
.it66 websites
.es50 websites
.de49 websites
.net47 websites
.fr45 websites
.pl40 websites
.co.uk39 websites
.nl32 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-13482

Top websites that are affected by CVE-2024-13482. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
******.**.id Indonesia***,***
**************.it Netherlands***,***
***********.com United States***,***
******.com United States***,***
*********.com Bangladesh***,***
********.es United States***,***
*****.fr United States***,***
************.org United States***,***
************.***.hk Hong Kong***,***
See full domain list

FAQ

CVE-2024-13482 is Improper Authentication in Icegram
A total of 1,826 websites have been identified as vulnerable to CVE-2024-13482, based on global website indexing conducted by WebTechSurvey.
The Icegram is affected by the CVE-2024-13482 vulnerability.
Icegram versions up to 3.1.32 are vulnerable to CVE-2024-13482.
CVE-2024-13482 is resolved in version 3.1.32 of Icegram.