VulnerabilityModified
CVE-2023-6000
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
MEDIUM 6.1EPSS 2.00%
Does this matter?
Lower severity and a low EPSS score (2.00%). Track it; it rarely justifies an emergency change on its own.
Description
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sygnoos/popup builder
- Source
- contact@wpscan.com
References
- https://wpscan.com/blog/stored-xss-fixed-in-popup-builder-4-2-3/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/cdb3a8bd-4ee0-4ce0-9029-0490273bcfc8Exploit, Third Party Advisory
- https://wpscan.com/blog/stored-xss-fixed-in-popup-builder-4-2-3/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/cdb3a8bd-4ee0-4ce0-9029-0490273bcfc8Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.