SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2025-15692

LOW · CVSS 3.5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Icegram Express WordPress plugin versions prior to 5.8.6 are vulnerable to Stored Cross-Site Scripting due to improper escaping of a list description setting in HTML attributes. This flaw allows users with Administrator privileges to inject malicious scripts, potentially compromising site integrity. WordPress site administrators should prioritize this update to mitigate the risk of exploitation.

CVE
CVE-2025-15692
Severity
LOW
CVSS
3.5
EPSS
0.17%
WordPress

Original NVD Description

The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.