CVE-2024-3231
17.05.2024, 06:15
The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
Vendor | Product | Version |
---|---|---|
ivanweb | popup4phone | 𝑥 ≤ 1.3.2 |
𝑥
= Vulnerable software versions