First published: Mon Nov 29 2021(Updated: )
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Essentialplugin Popup Anything | <2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24883 has a high severity due to its potential for Cross-Site Scripting attacks.
To fix CVE-2021-24883, update the Popup Anything WordPress plugin to version 2.0.4 or later.
CVE-2021-24883 affects the Popup Anything WordPress plugin prior to version 2.0.4.
Users with a role as low as Contributor can exploit CVE-2021-24883.
CVE-2021-24883 is a Cross-Site Scripting (XSS) vulnerability.