"Hackers Exploit WordPress Plugin Flaw to Infect 3,300 Sites With Malware"
"Hackers Exploit WordPress Plugin Flaw to Infect 3,300 Sites With Malware"
According to security researchers at Sucuri, hackers are breaching WordPress sites by exploiting a vulnerability in outdated versions of the Popup Builder plugin, infecting over 3,300 websites with malicious code. The researchers noted that the flaw leveraged in the attacks is tracked as CVE-2023-6000, a cross-site scripting (XSS) vulnerability impacting Popup Builder versions 4.2.3 and older, which was initially disclosed in November 2023.