cve/2024/CVE-2024-12302.md
2025-09-29 21:09:30 +02:00

859 B

CVE-2024-12302

Description

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks

POC

Reference

Github