The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. However, version 1.3.6 incorporates the correct authorization check to prevent unauthorized access.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.78395}

epss

{'score': 0.7938}


Wed, 30 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:themehunk:wp_popup_builder:*:*:*:*:*:wordpress:*:*

Wed, 16 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Themehunk
Themehunk wp Popup Builder
CPEs cpe:2.3:a:themehunk:wp_popup_builder:*:*:*:*:*:*:*:*
Vendors & Products Themehunk
Themehunk wp Popup Builder
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 07:45:00 +0000

Type Values Removed Values Added
Description The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. However, version 1.3.6 incorporates the correct authorization check to prevent unauthorized access.
Title WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-10-16T18:02:58.970Z

Reserved: 2024-09-20T21:31:38.100Z

Link: CVE-2024-9061

cve-icon Vulnrichment

Updated: 2024-10-16T17:20:21.050Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-16T08:15:07.323

Modified: 2024-10-30T21:11:17.450

Link: CVE-2024-9061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.