CVE-2024-9061

HIGH NUCLEI

Themehunk WP Popup Builder < 1.3.6 - Code Injection

Title source: rule

Description

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. However, version 1.3.6 incorporates the correct authorization check to prevent unauthorized access.

Exploits (1)

nomisec WORKING POC 3 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9061

Nuclei Templates (1)

WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution
HIGHVERIFIEDby s4e-io
FOFA: body="/wp-content/plugins/wp-popup-builder/"

Scores

CVSS v3 7.3
EPSS 0.8900
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-94
Status published
Products (2)
themehunk/wp_popup_builder < 1.3.6
themehunk/WP Popup Builder – Popup Forms and Marketing Lead Generation < 1.3.5
Published Oct 16, 2024
Tracked Since Feb 18, 2026