Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54254 | The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup). |
Thu, 24 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T16:10:06.020Z
Reserved: 2023-08-16T18:31:54.690Z
Link: CVE-2023-4390
Updated: 2024-08-02T07:24:04.709Z
Status : Modified
Published: 2023-10-31T14:15:11.990
Modified: 2025-04-23T17:16:44.423
Link: CVE-2023-4390
No data.
OpenCVE Enrichment
No data.
EUVD