CVE-2025-47527 PUBLISHED

WordPress Icegram Collect – Easy Form, Lead Collection and Subscription plugin <= 1.3.18 - Broken Access Control Vulnerability

Assigner: Patchstack
Reserved: 07.05.2025 Published: 09.06.2025 Updated: 09.06.2025

Missing Authorization vulnerability in Icegram Icegram Collect – Easy Form, Lead Collection and Subscription plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Icegram Collect – Easy Form, Lead Collection and Subscription plugin: from n/a through 1.3.18.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVSS Score: 7.1

Product Status

Vendor Icegram
Product Icegram Collect – Easy Form, Lead Collection and Subscription plugin
Versions Default: unaffected
  • affected from n/a to 1.3.18 (incl.)

Solutions

Update the WordPress Icegram Collect – Easy Form, Lead Collection and Subscription plugin plugin to the latest available version (at least 1.3.19).

Credits

  • ch4r0n (Patchstack Alliance) finder

References

Problem Types

  • CWE-862 Missing Authorization CWE

Impacts

  • CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels