Security readout for executives and security teams
Plain-English summary
CVE-2019-15830 is a cross-site scripting issue in the Icegram WordPress plugin before version 1.10.29. Affected sites may allow injected script content through the ig_cat_list area. The source bundle does not provide CVSS, authentication requirements, or confirmed exploitation evidence.
Executive priority
Treat as a routine but time-sensitive web application hygiene issue. Prioritize externally reachable WordPress sites, especially those used for marketing, customer engagement, or lead capture, because XSS can affect visitor trust and administrative sessions.
Technical view
The CVE record describes XSS in the Icegram plugin before 1.10.29, specifically tied to ig_cat_list. The Sucuri reference indicates a persistent XSS context, but the supplied bundle does not include exploit mechanics, affected code paths, privileges required, or impact scoring.
Likely exposure
Exposure is most likely on WordPress sites running the Icegram plugin earlier than 1.10.29. The bundle does not identify specific CPEs, hosting patterns, or whether unauthenticated users can reach the vulnerable path.
Exploitation context
The CVE is not listed as KEV in the supplied data. No cited source in the bundle states active exploitation. Public vulnerability references exist, so defenders should assume attackers may understand the issue, but not claim active exploitation from this evidence.
Researcher notes
Evidence is sparse: no CVSS, CWE, CPE, privilege requirement, or detailed patch note is included. The safest conclusion is version-based exposure for Icegram before 1.10.29, with remediation through vendor update verification rather than inferred code-level fixes.
Mitigation direction
- Inventory WordPress sites for the Icegram plugin and installed version.
- Update Icegram to version 1.10.29 or later if still in use.
- Review vendor plugin notes for any additional remediation guidance.
- Disable or remove Icegram where it is unnecessary or unsupported.
Validation and detection
- Confirm no production site runs Icegram below version 1.10.29.
- Review WordPress admin users and recent plugin configuration changes.
- Check web logs for suspicious requests involving ig_cat_list.
- Verify security monitoring covers unexpected script injection symptoms.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-15830 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://wpvulndb.com/vulnerabilities/9440CVE reference · x_refsource_MISC
- https://wordpress.org/plugins/icegram/#developersCVE reference · x_refsource_MISC
- https://blog.sucuri.net/2019/07/icegram-persistent-cross-site-scripting.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
