CVE-2025-0671 — The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Script — CVE Database · The Intelligence Room