Popup Like box < 3.6.1 - Reflected Cross-Site Scripting
CVE-2022-0641
6.1MEDIUM
What is CVE-2022-0641?
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Affected Version(s)
Popup Like box – Page Plugin 3.6.1