CVE-2022-3690


Popup Maker < 1.16.11 - Contributor+ Stored Cross Site Scripting

The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins



We have discovered 48,743 live websites that are affected by CVE-2022-3690.

Contact us to get more info




Affected Software

Product  Popup Maker
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 1.16.11
Total Vulnerable Versions117
Vulnerable Domains48,743 live websites (30.85% of Popup Maker install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-3690 and the relative popularity of websites


Details

  • Published - Nov 21, 2022
  • Updated - Dec 8, 2022

Credits

  • c3p0d4y (finder)





Countries

United States11,535 websites



Russia5,972 websites
Germany2,577 websites
Italy2,531 websites
France2,229 websites
India1,883 websites
GB1,861 websites
Australia1,551 websites
Spain1,433 websites
Poland1,372 websites

TLDs

.com19,059 websites
.ru4,753 websites
.org1,938 websites
.it1,642 websites
.de1,591 websites
.com.au1,220 websites
.co.uk1,024 websites
.pl1,002 websites
.fr926 websites
.com.br810 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-3690 through included software libraries and plugins.



References


Websites affected by CVE-2022-3690

Top websites that are affected by CVE-2022-3690. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.com United States*,***
***.*********.com United States*,***
***.*******.com France**,***
**********.**.il Israel**,***
***.*************.com United States**,***
***.**************.ca Canada**,***
***.********.com United States**,***
***.***.com United States**,***
***.***********.com United States**,***
***********.com United States**,***
See full domain list