Vulnerabilities > Poptin > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-10-20 CVE-2023-4961 Cross-site Scripting vulnerability in Poptin Popups
The Poptin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'poptin-form' shortcode in versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
poptin CWE-79
5.4