What the vulnerability does
01Description
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.
Explanation of Vulnerability in Simple Terms
An authenticated administrator with high privileges can trigger arbitrary code execution in the Popup Box plugin by uploading a malicious file. The vulnerability requires the attacker to have admin-level access and the site owner to interact with a crafted request. This allows complete compromise of the WordPress installation.
What an attacker can do
Run arbitrary code on the WordPress site with full admin privileges.
Potential impact on your site
An admin account compromise could lead to complete site takeover, data theft, or malware injection affecting all site visitors.
Conditions required to exploit
Attacker must have administrator access and trick a site owner into clicking a malicious link or visiting a crafted page.
Key dates
External resources