Vulnerabilities
Vulnerable Software
Ivanweb:  >> Popup4phone  Security Vulnerabilities
The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.
CVSS Score
6.1
EPSS Score
0.012
Published
2024-05-17
The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVSS Score
6.1
EPSS Score
0.001
Published
2024-05-17


Contact Us

Shodan ® - All rights reserved