CVE-2024-2544

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscribers, and importing subscribers to conduct stored cross-site scripting attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 09:09

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 7.4
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3096000%40popup-builder%2Ftrunk&old=3085485%40popup-builder%2Ftrunk&sfp_email=&sfph_mail= - Patch () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3096000%40popup-builder%2Ftrunk&old=3085485%40popup-builder%2Ftrunk&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/04802c63-4a5d-4948-9ef1-cf89c4cc757e?source=cve - Patch, Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/04802c63-4a5d-4948-9ef1-cf89c4cc757e?source=cve - Patch, Third Party Advisory

08 Aug 2024, 15:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.4
v2 : unknown
v3 : 6.4
CWE CWE-862
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3096000%40popup-builder%2Ftrunk&old=3085485%40popup-builder%2Ftrunk&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3096000%40popup-builder%2Ftrunk&old=3085485%40popup-builder%2Ftrunk&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/04802c63-4a5d-4948-9ef1-cf89c4cc757e?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/04802c63-4a5d-4948-9ef1-cf89c4cc757e?source=cve - Patch, Third Party Advisory
CPE cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
First Time Sygnoos popup Builder
Sygnoos

17 Jun 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) El complemento Popup Builder para WordPress es vulnerable a modificaciones no autorizadas de datos y pérdida de datos debido a una falta de verificación de capacidad en todas las acciones AJAX. Esto hace posible que los atacantes autenticados, con acceso a nivel de suscriptor y superior, realicen múltiples acciones no autorizadas, como eliminar suscriptores e importar suscriptores para realizar ataques de cross-site scripting almacenado.

15 Jun 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-15 02:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2544

Mitre link : CVE-2024-2544

CVE.ORG link : CVE-2024-2544


JSON object : View

Products Affected

sygnoos

  • popup_builder
CWE
CWE-862

Missing Authorization