ZeroHour

CVE-2022-2405

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p21
Published
()
Modified
Description

The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup

Vendors
themehunk
Products
wp popup builder
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.