CVE · High

CVE-2023-6696 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6696 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2 Missing Authorization High 8.1 < 4.3.2 4.3.2 2024-06-14

CVE-2023-6696

The Popup Builder plugin for WordPress through version 4.3.1 contains a capability check vulnerability that enables authenticated users to access restricted functions. Although certain functions include nonce validation, the nonce is publicly accessible on user profile pages, allowing subscribers to bypass intended restrictions. This flaw permits subscribers to execute unauthorized actions such as removing other subscriber accounts and initiating blind Server-Side Request Forgery attacks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.