Back

MEDIUM

Popup Builder < 4.2.3 - Unauthenticated Stored XSS

Published Jan 1, 2024

Description

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jan 1, 2024
Updated Jun 18, 2025
Reserved Nov 7, 2023
CISA Vulnrichment
Updated Jan 16, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a