What the vulnerability does
01Description
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
Explanation of Vulnerability in Simple Terms
The Pop-ups WordPress plugin version 1.1.5 and earlier contains a flaw that allows authenticated users with low privileges to modify site content and disrupt service. An attacker with a basic user account can alter pop-up settings or data, affecting site functionality and user experience. Update to a version newer than 1.1.5 to resolve this issue.
What an attacker can do
Modify pop-up content and settings, or disrupt pop-up functionality on the site.
Potential impact on your site
Unauthorized changes to pop-ups could deface messaging, break user workflows, or cause service interruptions.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., Contributor or Author role).
Key dates
External resources
Related vulnerabilities