The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58536 The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 24 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352

Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Popup Builder
Popup Builder popup Builder
CPEs cpe:2.3:a:popup_builder:popup_builder:*:*:*:*:*:*:*:*
Vendors & Products Popup Builder
Popup Builder popup Builder
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 09 Oct 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Sygnoos
Sygnoos popup Builder
Weaknesses CWE-22
CWE-918
CPEs cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Sygnoos
Sygnoos popup Builder
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-04-24T15:43:33.724Z

Reserved: 2023-11-24T19:58:33.638Z

Link: CVE-2023-6294

cve-icon Vulnrichment

Updated: 2024-08-02T08:28:21.292Z

cve-icon NVD

Status : Modified

Published: 2024-02-12T16:15:08.167

Modified: 2025-04-24T16:15:25.777

Link: CVE-2023-6294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.