Vulnerabilities > AYS PRO > Popup Like BOX

DATE CVE VULNERABILITY TITLE RISK
2022-03-28 CVE-2022-0641 Cross-site Scripting vulnerability in Ays-Pro Popup Like BOX
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
network
ays-pro CWE-79
4.3