CVE-2022-4362: Popup Maker < 1.16.9 - Contributor+ Stored XSS via Shortcode
Published Jan 2, 2023
·Updated
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Affected Software
1 affected component
Code-atlantic Popup Maker Wordpress<1.16.9
Event History
Jan 2, 2023
CVE Published
via MITRE·09:49 PM
Data Sourced
via MITRE·09:49 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-4362.
2
What is the severity of CVE-2022-4362?
The severity of CVE-2022-4362 is medium (5.4).
3
What is the affected software?
The affected software is the Popup Maker WordPress plugin before version 1.16.9.
4
What is the risk of CVE-2022-4362?
CVE-2022-4362 allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
5
How can I fix CVE-2022-4362?
Update the Popup Maker WordPress plugin to version 1.16.9 or newer to fix CVE-2022-4362.