CVE-2022-2305
The WordPress Popup WordPress plugin through 1.9.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
Date published : 2022-08-01
https://wpscan.com/vulnerability/ea0180cd-e018-43ea-88b9-fa8e71bf34bf
