peter bassill · operator
$ cve CVE-2022-1104 JSON

CVE-2022-1104 EXPLOIT

4.8
MEDIUM · CVSS 3.1 · EPSS 56.4% (pctl 99)

Patch early

A public exploit exists.

Description

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Scoring

CVSS4.8 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS56.41% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2022-05-09
Last modified2026-06-17

Affected (1)

VendorProduct
code-atlanticpopup maker

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD