Input validation vulnerability in Popup Builder – Create highly converting, mobile friendly marketing popups. 4.2.6

The Popup Builder is a plugin for WordPress that helps create effective marketing popups for mobile devices. Unfortunately, it has a security issue called Stored Cross-Site Scripting, which affects all versions up to and including 4.2.6. This means that the plugin does not properly protect against harmful code being added to popups by users with certain permissions. As a result, attackers with contributor-level or higher access can inject their own code into popups and potentially harm users who view them.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.