NA

CVE-2023-6000

Published: 01/01/2024 Updated: 08/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Popup Builder WordPress plugin prior to 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sygnoos popup builder

Recent Articles

Hackers exploit WordPress plugin flaw to infect 3,300 sites with malware
BleepingComputer • Bill Toulas • 10 Mar 2024

Hackers exploit WordPress plugin flaw to infect 3,300 sites with malware By Bill Toulas March 10, 2024 11:38 AM 0 Hackers are breaching WordPress sites by exploiting a vulnerability in outdated versions of the Popup Builder plugin, infecting over 3,300 websites with malicious code. The flaw leveraged in the attacks is tracked as CVE-2023-6000, a cross-site scripting (XSS) vulnerability impacting Popup Builder versions 4.2.3 and older, which was initially disclosed in November 2023. A Balada Inje...