Description
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51490 | The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T01:27:54.511Z
Reserved: 2022-11-23T09:33:06.531Z
Link: CVE-2022-4125
No data.
Status : Modified
Published: 2022-12-19T14:15:12.593
Modified: 2024-11-21T07:34:37.547
Link: CVE-2022-4125
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD