The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
We have discovered 9,345 live websites that are affected by CVE-2024-9428.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 9,345 live websites (39.97% of Popup Builder install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 128 versions ( 97.71% of all versions) |
![]() | 3,239 websites |
![]() | 927 websites |
![]() | 645 websites |
![]() | 318 websites |
![]() | 293 websites |
![]() | 282 websites |
![]() | 276 websites |
![]() | 221 websites |
![]() | 215 websites |
![]() | 202 websites |
.com | 3,952 websites |
.org | 451 websites |
.de | 373 websites |
.it | 269 websites |
.com.br | 257 websites |
.ru | 244 websites |
.fr | 240 websites |
.co.uk | 220 websites |
.pl | 207 websites |
.com.au | 178 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***.domains | ![]() | *,*** | |
***************.pl | ![]() | **,*** | |
******.com | ![]() | **,*** | |
************.***.au | ![]() | **,*** | |
**********.net | ![]() | **,*** | |
*****.com | ![]() | **,*** | |
*****.io | ![]() | **,*** | |
********.nl | ![]() | ***,*** | |
*******.org | ![]() | ***,*** | |
******.group | ![]() | ***,*** |
FAQ