CVE-2022-1104

MEDIUM

Popup Maker < 1.16.5 - Authenticated Stored Cross-Site Scripting in Popup Settings

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-1104. PoCs published by Roel van Beurden.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in WordPress Plugin Popup Maker versions <1.16.5. The vulnerability allows high-privilege users to inject malicious scripts via the 'Cookie Time' field in popup settings, bypassing the unfiltered_html capability restriction.

Description

The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Exploits (1)

exploitdb WORKING POC
by Roel van Beurden · textwebappsphp
https://www.exploit-db.com/exploits/50876

This exploit demonstrates a persistent XSS vulnerability in WordPress Plugin Popup Maker versions <1.16.5. The vulnerability allows high-privilege users to inject malicious scripts via the 'Cookie Time' field in popup settings, bypassing the unfiltered_html capability restriction.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Popup Maker <1.16.5
Auth required
Prerequisites: Authenticated access to WordPress admin panel · High privilege user role (e.g., admin)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/4d4709f3-ad38-4519-a24a-73bc04b20e52

Scores

CVSS v3 4.8
EPSS 0.5390
EPSS Percentile 98.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
code-atlantic/popup_maker < 1.16.5
Published May 09, 2022
Tracked Since Feb 18, 2026