CVE-2022-4381


Popup Maker < 1.16.9 - Contributor+ Stored XSS via Subscription Form

The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks



We have discovered 47,254 live websites that are affected by CVE-2022-4381.

Contact us to get more info




Affected Software

Product  Popup Maker
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 1.16.9
Total Vulnerable Versions117
Vulnerable Domains47,254 live websites (29.91% of Popup Maker install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4381 and the relative popularity of websites


Details

  • Published - Jan 2, 2023
  • Updated - Jan 10, 2023

Credits

  • An Doan (finder)
  • WPScan (coordinator)





Countries

United States11,172 websites



Russia5,869 websites
Italy2,446 websites
Germany2,444 websites
France2,155 websites
India1,817 websites
GB1,789 websites
Australia1,498 websites
Spain1,387 websites
Poland1,328 websites

TLDs

.com18,456 websites
.ru4,667 websites
.org1,882 websites
.it1,584 websites
.de1,502 websites
.com.au1,179 websites
.co.uk983 websites
.pl967 websites
.fr897 websites
.com.br785 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-4381 through included software libraries and plugins.



References


Websites affected by CVE-2022-4381

Top websites that are affected by CVE-2022-4381. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.************.com United States*,***
***.*********.com United States*,***
***.*******.com France**,***
**********.**.il Israel**,***
***.*************.com United States**,***
***.**************.ca Canada**,***
***.********.com United States**,***
***.***.com United States**,***
***.***********.com United States**,***
***********.com United States**,***
See full domain list