The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ays_pb_upgrade_plugin' option with arbitrary data.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ays-pro
Ays-pro popup Box |
|
CPEs | cpe:2.3:a:ays-pro:popup_box:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Ays-pro
Ays-pro popup Box |
|
Metrics |
ssvc
|
Sat, 16 Nov 2024 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ays_pb_upgrade_plugin' option with arbitrary data. | |
Title | Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-16T02:02:31.802Z
Updated: 2024-11-19T15:18:56.196Z
Reserved: 2024-11-05T13:52:25.380Z
Link: CVE-2024-10861
Vulnrichment
Updated: 2024-11-18T21:53:02.488Z
NVD
Status : Awaiting Analysis
Published: 2024-11-16T03:15:14.967
Modified: 2024-11-18T17:11:17.393
Link: CVE-2024-10861
Redhat
No data.