First published: Mon Oct 16 2023(Updated: )
The Popup Builder WordPress plugin through 4.1.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WordPress | >=4.7<4.7.27 | |
WordPress WordPress | >=4.8<4.8.23 | |
WordPress WordPress | >=4.9<4.9.24 | |
WordPress WordPress | >=5.0<5.0.20 | |
WordPress WordPress | >=5.1<5.1.17 | |
WordPress WordPress | >=5.2<5.2.19 | |
WordPress WordPress | >=5.3<5.3.16 | |
WordPress WordPress | >=5.4<5.4.14 | |
WordPress WordPress | >=5.5<5.5.13 | |
WordPress WordPress | >=5.6<5.6.12 | |
WordPress WordPress | >=5.7<5.7.10 | |
WordPress WordPress | >=5.8<5.8.8 | |
WordPress WordPress | >=5.9<5.9.8 | |
WordPress WordPress | >=6.0<6.0.6 | |
WordPress WordPress | >=6.1<6.1.4 | |
WordPress WordPress | >=6.2<6.2.3 | |
WordPress WordPress | >=6.3<6.3.2 | |
>=4.7<4.7.27 | ||
>=4.8<4.8.23 | ||
>=4.9<4.9.24 | ||
>=5.0<5.0.20 | ||
>=5.1<5.1.17 | ||
>=5.2<5.2.19 | ||
>=5.3<5.3.16 | ||
>=5.4<5.4.14 | ||
>=5.5<5.5.13 | ||
>=5.6<5.6.12 | ||
>=5.7<5.7.10 | ||
>=5.8<5.8.8 | ||
>=5.9<5.9.8 | ||
>=6.0<6.0.6 | ||
>=6.1<6.1.4 | ||
>=6.2<6.2.3 | ||
>=6.3<6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5561 is medium with a CVSS score of 5.3.
The Popup Builder WordPress plugin versions 4.1.15 and earlier are affected.
A high privilege user such as an admin can exploit CVE-2023-5561 to perform Stored Cross-Site Scripting attacks.
Yes, CVE-2023-5561 can be exploited even when the unfiltered_html capability is disallowed.
Yes, make sure to update the Popup Builder WordPress plugin to version 4.1.16 or later to fix CVE-2023-5561.