CVE-2022-4381
Popup Maker < 1.16.9 - Contributor+ Stored XSS via Subscription FormThe Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
We have discovered 47,254 live websites that are affected by CVE-2022-4381.
Contact us to get more info
Common Weakness Enumeration
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Distribution by Website Rank
The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4381 and the relative popularity of websites