The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
History

Mon, 07 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Digireturn dn Popup
Weaknesses CWE-352
CPEs cpe:2.3:a:digireturn:dn_popup:*:*:*:*:*:wordpress:*:*
Vendors & Products Digireturn dn Popup

Tue, 03 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Digireturn
Digireturn dn-popup
CPEs cpe:2.3:a:digireturn:dn-popup:*:*:*:*:*:*:*:*
Vendors & Products Digireturn
Digireturn dn-popup
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Title DN Popup <= 1.2.2 - Settings Update via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-02T06:00:03.795Z

Updated: 2024-09-03T14:04:16.707Z

Reserved: 2024-08-12T00:12:53.155Z

Link: CVE-2024-7690

cve-icon Vulnrichment

Updated: 2024-09-03T14:04:09.059Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-02T08:15:06.117

Modified: 2024-10-07T15:56:07.910

Link: CVE-2024-7690

cve-icon Redhat

No data.