CVE Database /
CVE-2023-3226
CVE · Medium
CVE-2023-3226 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-3226
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 4.2.2
|
4.2.2 |
2023-08-28 |
—
|
CVE-2023-3226
The Popup Builder plugin for WordPress prior to version 4.2.2 contains a stored cross-site scripting vulnerability in its administrative settings that allows authenticated administrators to inject malicious scripts due to inadequate input validation and output encoding. These injected scripts execute when users visit affected pages, though the vulnerability is limited to multisite WordPress installations or those where the unfiltered_html capability has been restricted. The flaw requires administrator-level access or higher privileges to exploit.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings