CVE-2023-6696

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions contain a nonce check, the nonce can be obtained from the profile page of a logged-in user. This allows subscribers to perform several actions including deleting subscribers and perform blind Server-Side Request Forgery.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*

History

06 Aug 2024, 14:05

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset/3096000/popup-builder/trunk/com/classes/Ajax.php - () https://plugins.trac.wordpress.org/changeset/3096000/popup-builder/trunk/com/classes/Ajax.php - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/9f86ec30-7a9d-4c36-8559-bde331c8b958?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/9f86ec30-7a9d-4c36-8559-bde331c8b958?source=cve - Patch, Third Party Advisory
References () https://plugins.trac.wordpress.org/browser/popup-builder/tags/4.2.3/com/classes/Ajax.php - () https://plugins.trac.wordpress.org/browser/popup-builder/tags/4.2.3/com/classes/Ajax.php - Patch
CPE cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
First Time Sygnoos
Sygnoos popup Builder
CWE CWE-862

15 Jun 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-15 02:15

Updated : 2024-08-06 14:05


NVD link : CVE-2023-6696

Mitre link : CVE-2023-6696


JSON object : View

Products Affected

sygnoos

  • popup_builder
CWE
CWE-862

Missing Authorization