QID 154148
Date Published: 2024-02-13
QID 154148: WordPress Popup Builder Plugin: Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2023-6000)
Popup Builder is a WordPress plugin which helps user create high converting, promotional and informative popups, providing wide range of WordPress popup types, conditions, and events.
Affected version of Popup Builder does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
Affected Versions:
Popup Builder prior to version 4.2.3
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Popup Builder plugin running on the target application.
Successful exploitation of this vulnerability could allow attackers to perform any action the logged in administrator they targeted is allowed to do on the targeted site, including installing arbitrary plugins and creating new rogue Administrator users.
- Popup Builder Plugin Changelog -
wordpress.org/plugins/popup-builder/#developers
CVEs related to QID 154148
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Popup Builder Plugin |
|