| |
Vulnerability CVE-2022-2405
Published: 2022-09-26
| Description: |
The WP Popup Builder WordPress plugin through 1.2.8 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup |
Type:
CWE-352 (Cross-Site Request Forgery (CSRF))
References: |
https://wpscan.com/vulnerability/50037028-2790-47ee-aae1-faf0724eb917
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|