Vulnerabilities > Essentialplugin > Popup Anything > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-07-25 CVE-2022-2115 Unspecified vulnerability in Essentialplugin Popup Anything
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting
network
low complexity
essentialplugin
6.1
2021-11-29 CVE-2021-24883 Unspecified vulnerability in Essentialplugin Popup Anything
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
network
low complexity
essentialplugin
5.4