WordPress Plugin Security Update Advisory (CVE-2023-6000)

Overview

 

An update has been made available to address a vulnerability in the Popup Builder plugin in WordPress. users of affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2023-6000

  • Popup Builder 4.2.3 or below

 

Resolved Vulnerabilities

 

Unauthenticated Stored XSS vulnerability in the Popup Builder plugin (CVE-2023-6000) [1]

 

Vulnerability Patches

 

Vulnerability Patches were made available in the December 12, 2023 update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2023-6000

  • Popup Builder 4.2.3 and at least version 4.2.3

 

Referenced Sites

 

[1] Stored XSS Fixed In Popup Builder 4.2.3
https://wpscan.com/blog/stored-xss-fixed-in-popup-builder-4-2-3/
[2] Popup Builder – Create highly converting, mobile friendly marketing popups.
https://wordpress.org/plugins/popup-builder/