CVE-2023-6000: Popup Builder < 4.2.3 - Unauthenticated Stored XSS
Published Jan 1, 2024
·Updated
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
Affected Software
1 affected component
Sygnoos Popup Builder Wordpress<4.2.3
Event History
Jan 1, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
News Published
05:44 PM
Mar 10, 2024
News Published
via BleepingComputer·03:38 PM
News Published
via BleepingComputer·03:39 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-6000?
CVE-2023-6000 has a high severity rating due to its potential to enable Stored XSS attacks.
2
How do I fix CVE-2023-6000?
To fix CVE-2023-6000, update the Popup Builder plugin to version 4.2.3 or later.
3
What could happen if I don't address CVE-2023-6000?
If not addressed, CVE-2023-6000 could allow attackers to inject malicious JavaScript, compromising user data.
4
Which versions of the Popup Builder plugin are affected by CVE-2023-6000?
CVE-2023-6000 affects all versions of the Popup Builder plugin prior to 4.2.3.
5
Is CVE-2023-6000 a known issue among WordPress plugins?
Yes, CVE-2023-6000 is recognized as a significant vulnerability within the WordPress ecosystem.