ZeroHour

CVE-2022-0424

PoC
CVSS 3.1
5.3 medium
EPSS
3%p87
Published
()
Modified
Description

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

Vendors
supsystic
Products
popup
Ecosystems
WordPress
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.