The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins
We have discovered 36,451 live websites that are affected by CVE-2022-3690.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 36,451 live websites (19.72% of Popup Maker install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 107 versions ( 84.92% of all versions) |
![]() | 11,070 websites |
![]() | 5,849 websites |
![]() | 2,684 websites |
![]() | 1,811 websites |
![]() | 1,036 websites |
![]() | 940 websites |
![]() | 889 websites |
![]() | 821 websites |
![]() | 783 websites |
![]() | 713 websites |
.com | 13,544 websites |
.ru | 4,789 websites |
.org | 1,306 websites |
.de | 1,103 websites |
.com.au | 871 websites |
.pl | 810 websites |
.it | 799 websites |
.net | 632 websites |
.co.uk | 614 websites |
.fr | 604 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | **,*** | |
**********.**.il | ![]() | **,*** | |
**************.ca | ![]() | **,*** | |
********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*******.de | ![]() | **,*** | |
*****.io | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
****.*************.**.uk | ![]() | **,*** | |
*******.com | ![]() | **,*** |
FAQ