PT-2022-19103 · Unknown · Muneeb'S Custom Popup Builder
Ngo Van
+1
·
Published
2022-06-15
·
Updated
2023-07-21
·
CVE-2022-28612
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Muneeb's Custom Popup Builder plugin versions prior to 1.3.2
Description
The issue is related to an Improper Access Control vulnerability that leads to multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities. This means that users with contributor or higher user roles can exploit this issue.
Recommendations
For Muneeb's Custom Popup Builder plugin versions prior to 1.3.2, update to version 1.3.2 or later to resolve the issue.
Fix
Improper Access Control
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Muneeb'S Custom Popup Builder