First published: Mon May 09 2022(Updated: )
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Popup Maker | <1.16.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1104 is a vulnerability in the Popup Maker WordPress plugin before version 1.16.5 that allows high privilege users to perform Stored Cross-Site Scripting (XSS) attacks.
CVE-2022-1104 has a severity of medium with a CVSS score of 4.8.
CVE-2022-1104 allows high privilege users, such as admin, to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
To fix CVE-2022-1104, update the Popup Maker WordPress plugin to version 1.16.5 or later.
Yes, you can find additional information about CVE-2022-1104 at the following reference: [https://wpscan.com/vulnerability/4d4709f3-ad38-4519-a24a-73bc04b20e52]