The plugin does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
The custom-popup parameter needs to be the ID of an existing popup https://example.com/wp-admin/admin.php?page=wppb&pos-name=xxx"><script>alert(%2FXSS%2F)%3B<%2Fscript>&custom-popup=1
Krzysztof Zając
Krzysztof Zając
Yes
2022-09-05 (about 4 months ago)
2022-09-05 (about 4 months ago)
2022-09-30 (about 4 months ago)