S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Sep 16, 2025

CVE-2023-6000 Scanner

CVE-2023-6000 Scanner - Cross-Site Scripting (XSS) vulnerability in WordPress Popup Builder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6000
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Popup Builder
AFFECTED< 4.2.3SAFE ✓≥ 4.2.3
Updated Aug 22, 2026View on NVD →
Detail

WordPress Popup Builder is a widely used plugin that enables website owners to create customized popups on their WordPress sites. This tool is popular among marketers and web designers for its ease of use and flexibility in delivering engaging content to users. The plugin is often integrated with various other WordPress plugins and themes to augment site functionality. Its user-friendly interface allows non-technical users to effectively manage popups without extensive coding knowledge. However, like any web application, it is susceptible to vulnerabilities if not updated or configured correctly. Regular maintenance and security checks are vital to keep the plugin functioning securely.

Cross-Site Scripting (XSS) is a prevalent vulnerability that allows attackers to inject malicious scripts into webpages viewed by other users. In this case, unauthorized visitors can update existing popups in the WordPress Popup Builder with raw JavaScript. The injected scripts can execute actions on behalf of the users' browsers, potentially leading to compromised user sessions or altered website content. XSS vulnerabilities can be particularly damaging as they may lead to the execution of arbitrary code within the context of the affected site, risking user data privacy and integrity.

The technical details of this vulnerability pertain to the insufficient input validation in the popup update process within the WordPress Popup Builder plugin. Attackers can exploit this by submitting a crafted POST request containing malicious JavaScript code as a payload. The specific endpoint that handles popup updates is vulnerable to JavaScript injection because it fails to sanitize user-generated content adequately. Unauthorized users can perform these exploits due to missing privilege verification checks, making the system susceptible to stored XSS attacks.

If exploited by malicious actors, this vulnerability can lead to several adverse outcomes. Users visiting a compromised website may unwittingly execute the malicious scripts, leading to unauthorized access to sensitive data, session hijacking, and potential redirection to phishing sites. This can erode user trust and damage the website's reputation. Additionally, attackers could perform actions as the legitimate users, such as modifying settings or exfiltrating data, further impacting the site's integrity and confidentiality.

REFERENCES

Solution Advice
  • Upgrade WordPress Popup Builder to version 4.2.3 or later to mitigate the vulnerability.
  • Implement proper input validation and sanitization to prevent script injection in user inputs.
  • Regularly audit WordPress plugins and themes for potential vulnerabilities and apply security patches promptly.
  • Consider deploying a Web Application Firewall (WAF) to filter and monitor HTTP requests for malicious content.
  • Educate users on the importance of applying updates and security measures for web applications and plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.