What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
Explanation of Vulnerability in Simple Terms
The Popup Builder WordPress plugin through version 4.1.11 contains a cross-site request forgery (CSRF) vulnerability. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unauthorized actions within the plugin without the admin's knowledge or consent. This could allow modification of popup settings or other plugin configurations.
What an attacker can do
Trick a logged-in admin into performing unauthorized actions in the plugin via a malicious webpage.
Potential impact on your site
Popup settings or plugin configuration could be changed without your knowledge if you visit a malicious link.
Conditions required to exploit
Admin must visit attacker's webpage while logged into WordPress.
Key dates
External resources
Related vulnerabilities