Login/Signup Popup < 1.5 - Missing Authorization
43Vexday Risk Score
Prioriza la corrección. Ella explotación observada por VulnCheck.
ssvc Actcvss 7.4epss 0.7%
de la publicación al arma
Publicada en NVD7 jun
VulnCheck14 may
probabilidad de explotación
0.7%top 51% de las CVE
explotación observada
síVulnCheck
The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Productos afectados
xootix · Login & Register Customizer – Popup | Slider | Inline | WooCommerce