CVE-2023-6591: Popup Box Pro < 20.9.0 - Admin+ Stored XSS
Published Feb 12, 2024
·Updated
The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
1 affected component
ays-pro Popup Box Wordpress<20.9.0
Event History
Feb 12, 2024
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6591?
CVE-2023-6591 has been classified with a medium severity level due to its potential for Cross-Site Scripting attacks.
2
How do I fix CVE-2023-6591?
To fix CVE-2023-6591, update the Popup Box WordPress plugin to version 20.9.0 or later.
3
Who is affected by CVE-2023-6591?
CVE-2023-6591 affects installations of the Popup Box WordPress plugin prior to version 20.9.0.
4
What types of attacks can occur due to CVE-2023-6591?
CVE-2023-6591 can allow high privilege users to perform Cross-Site Scripting (XSS) attacks.
5
Does CVE-2023-6591 affect all WordPress users?
CVE-2023-6591 primarily affects high privilege users, such as administrators, using the vulnerable version of the plugin.