CVE-2022-0641: Popup Like box < 3.6.1 - Reflected Cross-Site Scripting
Published Mar 28, 2022
·Updated
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the aysfbtab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Affected Software
1 affected component
ays-pro Popup Like Box Wordpress<3.6.1
Event History
Mar 28, 2022
CVE Published
via MITRE·05:23 PM
Data Sourced
via MITRE·05:23 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Popup Like box WordPress plugin?
The vulnerability ID for the Popup Like box WordPress plugin is CVE-2022-0641.
2
What is the severity of CVE-2022-0641?
The severity of CVE-2022-0641 is medium with a severity value of 6.1.
3
What is the affected software for CVE-2022-0641?
The affected software for CVE-2022-0641 is the Popup Like box WordPress plugin before version 3.6.1.
4
What is the CWE ID for CVE-2022-0641?
The CWE ID for CVE-2022-0641 is CWE-79.
5
How can I fix the vulnerability in the Popup Like box WordPress plugin?
To fix the vulnerability, update the Popup Like box WordPress plugin to version 3.6.1 or later.