Popup Builder < 4.1.11 - Admin+ Stored Cross-Site Scripting
CVE-2022-1894
4.8MEDIUM
What is CVE-2022-1894?
The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed
Affected Version(s)
Popup Builder – Create highly converting, mobile friendly marketing popups. 4.1.11