CyberRota Analysis
AI analysis pending.
CVE
CVE-2022-4125
Severity
MEDIUM
CVSS
4.3
EPSS
0.29%
WordPress
Original NVD Description
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF check when creating/updating popups, and is missing sanitisation as well as escaping, which could allow unauthenticated attackers to create arbitrary popups and add Stored XSS payloads as well
Related CVEs
Other vulnerabilities affecting the same vendor(s)