CVE-2024-9599 brings to light a critical Stored Cross-Site Scripting (XSS) vulnerability within the WordPress Popup Box plugin, a popular tool used to create a variety of popups for websites. This plugin allows users to add visually appealing and engaging popups, ranging from promotional notifications to subscription forms, without requiring extensive technical knowledge. However, an identified flaw in the way the plugin handles input parameters allows malicious users to inject JavaScript code, leading to the potential creation of backdoors within the WordPress environment. The implications of this vulnerability could lead to unauthorized access and control over affected websites.
CVE-2024-9599 – Popup Box – Stored XSS to Backdoor Creation – POC
![CVE-2024-9599 – Popup Box – Stored XSS to Backdoor Creation – POC CVE-2024-9599 – Popup Box – Stored XSS to Backdoor Creation – POC](https://research.cleantalk.org/wp-content/uploads/2023/10/New_1_not_safe-1.png)