CVE Database /
CVE-2023-6696
CVE · High
CVE-2023-6696 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-6696
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2 |
Missing Authorization |
High
8.1
|
< 4.3.2
|
4.3.2 |
2024-06-14 |
—
|
CVE-2023-6696
The Popup Builder plugin for WordPress through version 4.3.1 contains a capability check vulnerability that enables authenticated users to access restricted functions. Although certain functions include nonce validation, the nonce is publicly accessible on user profile pages, allowing subscribers to bypass intended restrictions. This flaw permits subscribers to execute unauthorized actions such as removing other subscriber accounts and initiating blind Server-Side Request Forgery attacks.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings