First published: Mon Jan 02 2023(Updated: )
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Popup Maker | <1.16.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-4362.
The severity of CVE-2022-4362 is medium (5.4).
The affected software is the Popup Maker WordPress plugin before version 1.16.9.
CVE-2022-4362 allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
Update the Popup Maker WordPress plugin to version 1.16.9 or newer to fix CVE-2022-4362.