ZeroHour

CVE-2023-6000

PoC ×2
CVSS 3.1
6.1 medium
EPSS
2%p80
Published
()
Modified
Description

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

Vendors
sygnoos
Products
popup builder
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news