Stored Cross-site Scripting Flaw in 5 Star Plugins Pretty Simple Popup Builder
CVE-2024-56298
What is CVE-2024-56298?
A vulnerability exists in the Pretty Simple Popup Builder plugin developed by 5 Star Plugins, which can lead to Stored Cross-site Scripting (XSS) attacks. This flaw allows attackers to inject malicious scripts into web pages that can be executed when users interact with the popup. It affects versions from n/a up to 1.0.9, posing significant risks for websites utilizing this plugin, as it can compromise user data and session hijacking. Website owners are strongly advised to update their plugins to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pretty Simple Popup Builder <= 1.0.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved