CVE Database /
CVE-2021-24152
CVE · Medium
CVE-2021-24152 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.74
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24152
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.74 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 3.74
|
3.74 |
2021-02-02 |
—
|
CVE-2021-24152
The Popup Builder plugin before version 3.74 contained a reflected cross-site scripting vulnerability in its "All Subscribers" settings page. An attacker could exploit this flaw by crafting a malicious link that, when clicked by an authenticated user, would execute arbitrary JavaScript code in the context of their browser session. This vulnerability could allow attackers to steal sensitive information or perform unauthorized actions on behalf of affected users.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings