QID 731097
Date Published: 2024-01-24
QID 731097: WordPress Plugin Popup Builder Cross-Site Scripting (XSS) Vulnerability
Popup Builder is a Perfect solution for any WordPress website. With a wide range of WordPress popup types, conditions, and events (From Image Popup to Countdown popup, Exit Intent to GeoTargeting) Popup Builder helps you create high converting, promotional and informative popups, increase conversion rates and boost sales while reaching your marketing goals.
CVE-2023-6000 : The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
Affected Versions:
WordPress Popup Builder plugin versions prior to 4.2.3
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Popup Builder Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability may allow attackers to perform any action the logged in administrator they targeted is allowed to do on the targeted site including installing arbitrary plugins and creating new rogue Administrator users.
- WP Popup-Builder Plugin Release Notes -
wordpress.org/plugins/popup-builder/#developers
CVEs related to QID 731097
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Popup Builder plugin |
|