CVE-2022-4125
19.12.2022, 14:15
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well
Vendor | Product | Version |
---|---|---|
popup_manager_project | popup_manager | 𝑥 ≤ 1.6.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration