CVE-2024-4045

Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation <= 2.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘campaign_id’ parameter in versions up to, and including, 2.16.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 624 live websites that are affected by CVE-2024-4045.

Run a Free Instant Scan




Affected Software

Product  Popup Builder
Category Wordpress Plugins
Vulnerable Domains624 live websites (11% of Popup Builder install base)
Vulnerable Versions
  • from 0 through 2.16.1
Vulnerable Versions Count54 versions ( 75% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 25, 2024
  • Updated - Apr 8, 2026

Credits

  • wesley (finder)

Website Distribution by Country

Number of websites using CVE-2024-4045
United States431 websites



GB24 websites
Germany19 websites
France16 websites
Australia13 websites
Canada10 websites
Netherlands9 websites
Denmark8 websites
Spain8 websites
Italy7 websites

Website Distribution by TLD

Number of websites using CVE-2024-4045
.com412 websites
.org43 websites
.co.uk15 websites
.net14 websites
.com.au14 websites
.co7 websites
.de7 websites
.ca6 websites
.nl6 websites
.dk6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-4045

Top websites that are affected by CVE-2024-4045. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.org United States*,***
*********.com United States**,***
*************.com United States**,***
********.com United States**,***
***.*********.me United States**,***
************.**.uk GB**,***
***************.com United States**,***
*****************.com United States**,***
**********************.com United States***,***
******.com United States***,***
See full domain list

FAQ

CVE-2024-4045 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Popup Builder
A total of 624 websites have been identified as vulnerable to CVE-2024-4045, based on global website indexing conducted by WebTechSurvey.
The Popup Builder is affected by the CVE-2024-4045 vulnerability.
Popup Builder versions up to and including 2.16.1 are vulnerable to CVE-2024-4045.