CVE-2023-6000
MEDIUM EXPLOITED NUCLEIPopup Builder < 4.2.3 - Unauthenticated Stored Cross-Site Scripting via Popup Update
Title source: llmExploitation Summary
CVE-2023-6000 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including RonF98. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2023-6000, a stored XSS vulnerability in the WordPress Popup Builder plugin (<4.2.3). The exploit demonstrates how an attacker can inject malicious JavaScript into a popup, which executes when users interact with it.
Description
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
Exploits (1)
This repository provides a functional proof-of-concept for CVE-2023-6000, a stored XSS vulnerability in the WordPress Popup Builder plugin (<4.2.3). The exploit demonstrates how an attacker can inject malicious JavaScript into a popup, which executes when users interact with it.
Nuclei Templates (1)
body="/wp-content/plugins/popup-builder"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N