CVE-2022-2405
26.09.2022, 13:15
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
| Vendor | Product | Version |
|---|---|---|
| themehunk | wp_popup_builder | 𝑥 < 1.2.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration