The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
id: CVE-2023-6000
info:
name: WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSS
aut
...