CVE-2021-24152: Popup Builder < 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)
Published Apr 5, 2021
·Updated
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
Affected Software
1 affected component
Sygnoos Popup Builder Wordpress<3.74
Event History
Apr 5, 2021
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Popup Builder plugin?
The vulnerability ID for the Popup Builder plugin is CVE-2021-24152.
2
What is the severity of CVE-2021-24152?
CVE-2021-24152 has a severity rating of medium.
3
What is the affected software for CVE-2021-24152?
The affected software for CVE-2021-24152 is Sygnoos Popup Builder version up to 3.74 for WordPress.
4
What type of vulnerability is CVE-2021-24152?
CVE-2021-24152 is a reflected Cross-Site Scripting (XSS) vulnerability.
5
How can I fix the vulnerability in Popup Builder?
To fix the vulnerability in Popup Builder, update to a version higher than 3.74.