CVE-2023-6000


Popup Builder < 4.2.3 - Unauthenticated Stored XSS

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.



We have discovered 690 live websites that are affected by CVE-2023-6000.

Contact us to get more info




Affected Software

Product  Popup Builder
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 4.2.3
Total Vulnerable Versions95
Vulnerable Domains690 live websites (16.22% of Popup Builder install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-6000 and the relative popularity of websites


Details

  • Published - Jan 1, 2024
  • Updated - Jan 1, 2024

Credits

  • Marc Montpas (finder)
  • WPScan (coordinator)





Countries

United States202 websites



Germany51 websites
France49 websites
Italy34 websites
Poland28 websites
India27 websites
Russia26 websites
GB26 websites
Spain21 websites
Canada16 websites

TLDs

.com311 websites
.org53 websites
.de28 websites
.it26 websites
.ru23 websites
.pl20 websites
.fr15 websites
.co.uk14 websites
.net13 websites
.com.br12 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-6000 through included software libraries and plugins.



References


Websites affected by CVE-2023-6000

Top websites that are affected by CVE-2023-6000. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.com GB**,***
***.*************.com France***,***
***.*********.com India***,***
*****.***.tr Turkey***,***
***.****.org United States***,***
***.********.com Germany***,***
***.********.org United States***,***
***.********.com United States***,***
***.*****.com United States***,***
********.africa South Africa***,***
See full domain list