CVE-2022-1776: Icegram < 2.1.8 - Contributor+ Stored Cross-Site Scripting
The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1776?
CVE-2022-1776 is a vulnerability found in the Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before version 2.1.8.
What is the severity of CVE-2022-1776?
CVE-2022-1776 has a severity level of medium with a CVSS score of 5.4.
Who is affected by CVE-2022-1776?
Users of the Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin version up to 2.1.8 are affected by CVE-2022-1776.
What is the impact of CVE-2022-1776?
CVE-2022-1776 allows users with a role as low as contributor to perform Stored Cross-Site Scripting (XSS) attacks.
How can I fix CVE-2022-1776?
To fix CVE-2022-1776, update the Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin to version 2.1.8 or later.