NA

CVE-2022-4125

Published: 19/12/2022 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Popup Manager WordPress plugin up to and including 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated malicious users to create arbitrary popups and add Stored XSS payloads as well

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

popup manager project popup manager