HTTP: WordPress Popup Maker Plugin Popup Settings Stored Cross-Site Scripting

This signature detects attempts to exploit a known cross-site scripting vulnerability against WordPress Popup Maker Plugin. It is due to insufficient validation of user-supplied input. Attackers can steal cookie-based authentication credentials and launch other attacks.

Extended Description

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected Products

Code-atlantic popup_maker

References

CVE: CVE-2022-1104

Short Name
HTTP:XSS:WORDPRESS-POPUP
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2022-1104 Cross-Site Maker Plugin Popup Scripting Settings Stored WordPress
Release Date
10/27/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3631
False Positive
Unknown
Vendors

Code-atlantic

Found a potential security threat?