CVE-2023-3226: Popup Builder < 4.2.0 - Admin+ Stored Cross-Site Scripting
The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Other sources
The Popup Builder WordPress plugin through 4.1.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3226?
CVE-2023-3226 is a vulnerability in the Popup Builder WordPress plugin through version 4.1.15.
What is the severity of CVE-2023-3226?
CVE-2023-3226 has a severity value of 4.8, indicating a medium severity.
How does CVE-2023-3226 affect WordPress?
CVE-2023-3226 affects the Popup Builder WordPress plugin version 4.1.15 and below.
What is a Stored Cross-Site Scripting (XSS) attack?
A Stored Cross-Site Scripting (XSS) attack is a type of vulnerability that allows attackers to inject malicious scripts into web pages that are permanently stored on a target website.
How can I fix CVE-2023-3226 in the Popup Builder WordPress plugin?
To fix CVE-2023-3226, update the Popup Builder WordPress plugin to version 4.1.16 or higher.