
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
This template looks at the following path: /wp-content/plugins/popup-builder/readme.txt
Based on the Stable Tag listed, if the version is prior to 4.2.3 then it is considered to be vulnerable.
nuclei -u https://yourHost.com -t template.yamlUse at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
If you have any questions please do reach out to me via Signal or via email: [email protected].
If you'd like to support my work, feel free to donate via Buy Me a Coffee — your support means a lot and is truly appreciated!