CVE-2022-4124

The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:popup_manager_project:popup_manager:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-12-19 06:15

Updated : 2022-12-22 14:04


NVD link : CVE-2022-4124

Mitre link : CVE-2022-4124


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

popup_manager_project

  • popup_manager