CVE-2024-9428

Popup Builder < 4.3.5 - Admin+ Stored XSS

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).


We have discovered 9,345 live websites that are affected by CVE-2024-9428.

Test my site




Affected Software

Product  Popup Builder
Category Wordpress Plugins
Vulnerable Domains9,345 live websites (39.97% of Popup Builder install base)
Vulnerable Versions
  • from 0 before 4.3.5
Vulnerable Versions Count128 versions ( 97.71% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Dec 12, 2024
  • Updated - Dec 12, 2024

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

CVE-2024-9428 usage by Country

United States3,239 websites



Germany927 websites
France645 websites
Italy318 websites
GB293 websites
Russia282 websites
Poland276 websites
Cyprus221 websites
Brazil215 websites
Spain202 websites

CVE-2024-9428 usage by TLD

.com3,952 websites
.org451 websites
.de373 websites
.it269 websites
.com.br257 websites
.ru244 websites
.fr240 websites
.co.uk220 websites
.pl207 websites
.com.au178 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-9428

Top websites that are affected by CVE-2024-9428. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.domains United States*,***
***************.pl Poland**,***
******.com United States**,***
************.***.au United States**,***
**********.net United States**,***
*****.com GB**,***
*****.io United States**,***
********.nl Netherlands***,***
*******.org United States***,***
******.group Cyprus***,***
See full domain list

FAQ

CVE-2024-9428 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Popup Builder
A total of 9,345 websites have been identified as vulnerable to CVE-2024-9428, discovered through global website indexing conducted by WebTechSurvey.
Popup Builder is susceptible to CVE-2024-9428 vulnerability.
Popup Builder versions before 4.3.5 are vulnerable to CVE-2024-9428.
Version 4.3.5 of Popup Builder addresses the CVE-2024-9428 security vulnerability.