CVE-2024-5004

CVE-2024-5004: CM Popup Plugin for WordPress < 1.6.6 - Contributor+ Stored XSS

Vendor Unknown
Product CM Popup Plugin for WordPress
Published July 22, 2024
Last update August 1, 2024

CVSS base score

What the vulnerability does

01Description

The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

Key dates

02Disclosure timeline

July 22, 2024 CVE published
August 1, 2024 Record updated