The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-01T14:18:56.633Z

Updated: 2024-01-01T14:18:56.633Z

Reserved: 2023-11-07T20:31:29.006Z


Link: CVE-2023-6000

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-01T15:15:43.100

Modified: 2024-01-08T15:14:56.640


Link: CVE-2023-6000

JSON object: View

cve-icon Redhat Information

No data.

CWE