WordPress Plugin Security Update Advisory (CVE-2023-6000)
Overview
An update has been made available to address a vulnerability in the Popup Builder plugin in WordPress. users of affected versions are advised to update to the latest version.
Affected Products
CVE-2023-6000
- Popup Builder 4.2.3 or below
Resolved Vulnerabilities
Unauthenticated Stored XSS vulnerability in the Popup Builder plugin (CVE-2023-6000) [1]
Vulnerability Patches
Vulnerability Patches were made available in the December 12, 2023 update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2023-6000
- Popup Builder 4.2.3 and at least version 4.2.3
Referenced Sites
[1] Stored XSS Fixed In Popup Builder 4.2.3
https://wpscan.com/blog/stored-xss-fixed-in-popup-builder-4-2-3/
[2] Popup Builder – Create highly converting, mobile friendly marketing popups.
https://wordpress.org/plugins/popup-builder/