cleantalk
Vulnerabilities and Security Researches

Popup Maker – Popup for opt-ins, lead gen, & more, 138af3136b67b000f20b74ce5d3071ef77150667

Published on
Sep 26, 2022
Research Description
Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.16.9 Popup Maker <= 1.16.8 - Authenticated (Contributor+) Cross-Site Scripting The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup body content in versions up to, and including, 1.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.16.9.
Status
vulnerable