The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
-
Updated
Oct 14, 2025
The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.
Example Django web application with Beefree SDK embedded.
Comprehensive documentation for the Beefree SDK — the most flexible and scalable embeddable builder for no-code email, landing pages, and popups. Integrate drag-and-drop editing into your app with full customization capabilities.
Add a description, image, and links to the popup-builder topic page so that developers can more easily learn about it.
To associate your repository with the popup-builder topic, visit your repo's landing page and select "manage topics."