The Icegram Engage plugin for WordPress has a second-order SQL injection vulnerability via the 'messages[][id]' parameter in versions up to and including 3.1.42. This allows authenticated attackers with contributor-level access to inject malicious SQL queries. The vulnerability arises from insufficient escaping of user-supplied parameters and lack of preparation on existing SQL queries. The attack involve [truncated]
The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs() function. The vulnerability allows authenticated attackers with Administrator-level access to [truncated]