{ "id": "CVE-2023-6000", "sourceIdentifier": "contact@wpscan.com", "published": "2024-01-01T15:15:43.100", "lastModified": "2024-01-01T15:15:43.100", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks." } ], "metrics": {}, "references": [ { "url": "https://wpscan.com/blog/stored-xss-fixed-in-popup-builder-4-2-3/", "source": "contact@wpscan.com" }, { "url": "https://wpscan.com/vulnerability/cdb3a8bd-4ee0-4ce0-9029-0490273bcfc8", "source": "contact@wpscan.com" } ] }