Vulnerability Description
The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Code-Atlantic | Popup Maker | < 1.16.11 |
References
- https://wpscan.com/vulnerability/725f6ae4-7ec5-4d7c-9533-c9b61b59cc2bExploitThird Party Advisory
- https://wpscan.com/vulnerability/725f6ae4-7ec5-4d7c-9533-c9b61b59cc2bExploitThird Party Advisory
FAQ
What is CVE-2022-3690?
CVE-2022-3690 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting...
How severe is CVE-2022-3690?
CVE-2022-3690 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3690?
Check the references section above for vendor advisories and patch information. Affected products include: Code-Atlantic Popup Maker.