CVE-2024-9428: Popup Builder < 4.3.5 - Admin+ Stored XSS
The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9428?
CVE-2024-9428 is rated as a high severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2024-9428?
To fix CVE-2024-9428, upgrade the Popup Builder WordPress plugin to version 4.3.5 or later.
Who is affected by CVE-2024-9428?
CVE-2024-9428 affects users of the Popup Builder WordPress plugin versions before 4.3.5.
What can attackers do with CVE-2024-9428?
Attackers can exploit CVE-2024-9428 to perform stored cross-site scripting attacks, potentially compromising user data.
What is the main issue with CVE-2024-9428?
The main issue with CVE-2024-9428 is the failure to sanitize and escape certain plugin settings, allowing high-privilege users to inject malicious scripts.