CVE-2023-5874: Popup box < 3.8.6 - Admin+ Stored XSS in Popup Settings
The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Popup box?
The vulnerability ID for Popup box is CVE-2023-5874.
What is the severity rating of CVE-2023-5874?
The severity rating of CVE-2023-5874 is medium.
What is the affected software for CVE-2023-5874?
The affected software for CVE-2023-5874 is the Popup box WordPress plugin version up to 3.8.6.
How can this vulnerability be exploited?
This vulnerability can be exploited by high privilege users, such as admins, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed.
Is there a fix available for CVE-2023-5874?
Yes, the fix for CVE-2023-5874 is to update the Popup box WordPress plugin to version 3.8.6 or higher.