Plugin Vulnerability Could Lead to Stored XSS Attacks
CVE-2023-6000
Key Information:
- Vendor
- Wordpress
- Status
- Vendor
- CVE Published:
- 1 January 2024
Badges
Summary
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
Affected Version(s)
Popup Builder 0 < 4.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
Get notified when SecurityVulnerability.io launches alerting π
Well keep you posted π§
News Articles
Malware Campaign Exploits Popup Builder WordPress Plugin to Infect 3,900+ Sites
WordPress sites under attack! A new malware campaign exploits Popup Builder plugin vulnerability (CVE-2023-6000) infecting over 3,900 sites
11 months ago
Nearly 7K WordPress Sites Compromised by Balada Injector
Nearly 200K WordPress sites could be vulnerable to the attack thanks to CVE-2023-6000, lurking in the PopUp Builder plug-in.
1 year ago
References
CVSS V3.1
Timeline
- π°
Used in Ransomware
- π‘
Public PoC available
- πΎ
Exploit known to exist
- π°
First article discovered by Dark Reading
Vulnerability published
Vulnerability Reserved