PoC Index

CVE-2023-6000

MEDIUM 6.1EPSS 2.0%

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
2.00% chance of exploitation in the next 30 days, 79th percentile
Nuclei
medium · CWE-79
Published
2024-01-01
Updated
2025-06-18

Proof-of-concept exploits (4)

Nuclei templates (1)

References

Related