CVE-2023-6696: Popup Builder – Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions contain a nonce check, the nonce can be obtained from the profile page of a logged-in user. This allows subscribers to perform several actions including deleting subscribers and perform blind Server-Side Request Forgery.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6696?
The severity of CVE-2023-6696 is considered high due to the unauthorized access it allows.
How do I fix CVE-2023-6696?
To fix CVE-2023-6696, update the Popup Builder plugin to version 4.3.2 or later.
What versions of Popup Builder are affected by CVE-2023-6696?
All versions of Popup Builder up to and including 4.3.1 are affected by CVE-2023-6696.
What are the implications of CVE-2023-6696?
The implications of CVE-2023-6696 include unauthorized access to plugin functionalities, which can lead to data leaks or website manipulation.
Is CVE-2023-6696 specific to any WordPress version?
CVE-2023-6696 is not specific to any WordPress version but affects the Popup Builder plugin across all versions.