vendor:
Popup Anything
by:
Luca Schembri
7.5
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Popup Anything
Affected Version From: < 2.0.4
Affected Version To: 2.0.3
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested: WordPress
2021
WordPress Plugin Popup Anything 2.0.3 – ‘Multiple’ Stored Cross-Site Scripting (XSS)
A user with a low privileged user can perform XSS-Stored attacks. Go on the 'Popup Anything - Settings' tab and select 'Simple Link' as 'Link Type'. Select 'Link Test' and use this payload: test" onclick="alert(1). Save the popup and reload the page. Now click on 'Link Text' and it will execute the javascript code. The same attack can be exploited with 'Button Text' and 'Popup width' fields.
Mitigation:
Upgrade to 2.0.4 version or later.