CVE-2023-3226


Popup Builder < 4.2.0 - Admin+ Stored Cross-Site Scripting

The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).



We have discovered 630 live websites that are affected by CVE-2023-3226.

Contact us to get more info




Affected Software

Product  Popup Builder
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 4.2
Total Vulnerable Versions95
Vulnerable Domains630 live websites (14.81% of Popup Builder install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-3226 and the relative popularity of websites


Details

  • Published - Sep 25, 2023
  • Updated - Dec 15, 2023

Credits

  • Dipak Panchal (th3.d1pak) (finder)
  • WPScan (coordinator)





Countries

United States186 websites



Germany47 websites
France46 websites
Italy31 websites
Poland28 websites
Russia26 websites
GB25 websites
India25 websites
Spain20 websites
Brazil12 websites

TLDs

.com291 websites
.org46 websites
.de25 websites
.ru23 websites
.it23 websites
.pl20 websites
.fr14 websites
.net13 websites
.co.uk13 websites
.com.br11 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-3226 through included software libraries and plugins.



References


Websites affected by CVE-2023-3226

Top websites that are affected by CVE-2023-3226. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.com GB**,***
***.*************.com France***,***
***.*********.com India***,***
*****.***.tr Turkey***,***
***.****.org United States***,***
***.********.com Germany***,***
***.********.org United States***,***
***.********.com United States***,***
***.*****.com United States***,***
********.africa South Africa***,***
See full domain list