cleantalk
Vulnerabilities and Security Researches

Popup Builder – Create highly converting, mobile friendly marketing popups., CVE-2022-1894

CVE, Research URL

CVE-2022-1894

Published on
Jul 11, 2022
Research Description
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed
Affected versions
max 4.1.11.
Status
vulnerable