PT-2025-51073 · WordPress · Popup Builder
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Popup Builder (Easy Notify Lite) versions prior to 1.1.38
Description
The Popup Builder (Easy Notify Lite) plugin for WordPress has a flaw that allows unauthorized modification of data. This is due to a missing capability check within the
easynotify cp reset() function. Attackers with Subscriber-level access or higher can reset the plugin’s settings to their default values.Recommendations
Update to version 1.1.38 or later.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Popup Builder