S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 29, 2024

CVE-2024-9061 Scanner

CVE-2024-9061 scanner - Code Injection vulnerability in WP Popup Builder Popup Forms and Marketing Lead Generation

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9061
7.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. However, version 1.3.6 incorporates the correct authorization check to prevent unauthorized access.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Popup Builder – Popup Forms and Marketing Lead Generationby themehunk
0
wp_popup_builderby themehunk
0
Updated Sep 10, 2026View on NVD →
Detail

The WP Popup Builder Popup Forms and Marketing Lead Generation plugin is widely used in WordPress sites for creating customizable popups and lead capture forms. Marketers and site administrators utilize this tool to generate leads, increase engagement, and enhance user interactivity. It is particularly popular for its easy-to-integrate marketing functionalities and wide range of customizable templates. With its flexible settings, users can adapt popup designs to match brand themes and goals. The plugin is supported by ThemeHunk and is actively updated to meet modern marketing needs.

This vulnerability allows attackers to inject and execute arbitrary shortcodes on WordPress sites running the WP Popup Builder plugin. Due to improper validation in the wp_ajax_nopriv_shortcode_Api_Add AJAX action, unauthenticated users can abuse the do_shortcode functionality to insert unwanted code. This exploit compromises the security of the site, potentially revealing sensitive information or enabling unauthorized actions. The severity level is high, making it crucial for affected sites to take preventive measures immediately.

The vulnerability stems from a flaw in the wp_ajax_nopriv_shortcode_Api_Add AJAX action, which lacks adequate validation for user input. This allows unauthenticated attackers to send specially crafted POST requests that trigger the do_shortcode function, thereby executing arbitrary code. The specific endpoint affected is /wp-admin/admin-ajax.php with a payload action of shortcode_Api_Add. The vulnerability is present due to the insufficient handling of the shortcode input, making it susceptible to code injection. Successful exploitation results in the site executing arbitrary shortcodes, potentially allowing further attacks.

Exploitation of this vulnerability could lead to severe security risks, including unauthorized access to sensitive site areas, manipulation of site content, or data disclosure. Additionally, attackers could use this vulnerability to implant backdoors, create unwanted popups or redirects, or inject malicious content. Such compromises may impact site credibility, result in data breaches, and lead to SEO penalties if malicious code is embedded on the website.

By using S4E’s advanced scanning platform, you gain unparalleled insights into potential security threats before they become severe. Our scanners detect various vulnerabilities, misconfigurations, and cyber risks across digital assets, helping you maintain a secure online presence. With automated scans and comprehensive reports, the platform simplifies vulnerability management and enables swift remediation actions. S4E empowers you to take proactive security measures, ensuring your site’s reliability, integrity, and trustworthiness. Become a member today to experience unmatched protection for your online assets.

References:

Solution Advice
  • Update the WP Popup Builder Popup Forms and Marketing Lead Generation plugin to the latest version to mitigate the vulnerability.
  • Limit access to the /wp-admin/admin-ajax.php endpoint to authorized users only.
  • Regularly review and apply security patches to WordPress plugins and core files.
  • Implement server-side validation checks for user inputs, especially those using AJAX actions.
  • Utilize a security plugin to monitor and block suspicious AJAX requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-9061 scanner - Code Injection vulnerability in WP Popup Builder Popup Forms and Marketing Lead Generation | S4E