The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.
History

Wed, 09 Oct 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Sygnoos
Sygnoos popup Builder
Weaknesses CWE-22
CWE-918
CPEs cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Sygnoos
Sygnoos popup Builder
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-02-12T16:06:01.185Z

Updated: 2024-08-02T08:28:21.292Z

Reserved: 2023-11-24T19:58:33.638Z

Link: CVE-2023-6294

cve-icon Vulnrichment

Updated: 2024-08-02T08:28:21.292Z

cve-icon NVD

Status : Modified

Published: 2024-02-12T16:15:08.167

Modified: 2024-11-21T08:43:33.060

Link: CVE-2023-6294

cve-icon Redhat

No data.