CVE-2023-6000 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Popup Builder WordPress plugin prior to version 4.2.3, allowing unauthenticated attackers to inject malicious JavaScript into existing popups. This medium-severity flaw (CVSS 6.1) has a low attack complexity and can lead to client-side compromise. The vulnerability is actively exploited in the wild, with reports of it being used to infect thousands of WordPress sites with malware, and public Nuclei templates are available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.3CPE matchmatch criteria | cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.