GHSA-qhh4-w7cp-9j2f
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 28, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.