Description
WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title field that execute when pages or posts display popup selections.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Unk9vvN
References
www.exploit-db.com/exploits/47518 (ExploitDB-47518)
popup-builder.com/ (Official Product Homepage)
wordpress.org/plugins/popup-builder/ (Product Reference)
www.vulncheck.com/...builder-persistent-cross-site-scripting (VulnCheck Advisory: WordPress Popup Builder 3.49 Persistent Cross-Site Scripting)