Loading HuntDB...

GHSA-wpxq-m249-cq6r

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

Related CVEs

Key Information

GHSA ID
GHSA-wpxq-m249-cq6r
Published
September 12, 2024 6:30 AM
Last Modified
September 12, 2024 9:32 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.