ZeroHour

CVE-2022-4124

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p20
Published
()
Modified
Description

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them

Vendors
popup manager project
Products
popup manager
Ecosystems
WordPress
Weakness
CWE-352, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.