Sploitus

CVE-2022-1104

2 known exploits for CVE-2022-1104

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected products
Popup Maker
Code-atlantic Popup Maker
< 1.16.5
Fix
Available
CVSS 3.1
4.8 MEDIUM
EPSS
56.4% (99th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2022-05-09
CVE-2022-1104 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2022-1104

Proof-of-concept code and exploit modules indexed by Sploitus