CVE-2023-6591
12.02.2024, 16:15
The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Vendor | Product | Version |
---|---|---|
ays-pro | popup_box | 𝑥 < 20.9.0 |
𝑥
= Vulnerable software versions