First published: Wed Jun 21 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Popup Box | <3.4.5 |
Update to 3.4.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27414 is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin versions up to 3.4.4.
CVE-2023-27414 has a severity keyword of 'high' and a severity value of 6.1.
CVE-2023-27414 affects Popup Box Team Popup box plugin versions up to 3.4.4.
To fix CVE-2023-27414, update your Popup Box Team Popup box plugin to version 3.4.5 or higher.
The Common Weakness Enumeration (CWE) for CVE-2023-27414 is CWE-79, which is the category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').