Vulnerability Details CVE-2024-3641
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.7%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2024-3641
-
cpe:2.3:a:mndpsingh287:newsletter_popup:1.1
-
cpe:2.3:a:mndpsingh287:newsletter_popup:1.2