Input validation vulnerability in Popup Builder – Create highly converting, mobile friendly marketing popups. 4.2.7

The Popup Builder plugin for WordPress, which helps create popups for marketing purposes, has a security vulnerability that allows attackers to inject harmful code into website pages. This can be done by using the custom JS functionality in versions up to 4.2.7, as the plugin does not properly filter and protect user-supplied attributes. This means that anyone with contributor-level access or higher can potentially add code that will run when someone visits the affected page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.