CVE · Medium

CVE-2022-29495 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-29495 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.12 Cross-Site Request Forgery (CSRF) Medium 5.4 < 4.1.12 4.1.12 2022-06-30

CVE-2022-29495

The Popup Builder plugin for WordPress versions up to 4.1.11 contains a cross-site request forgery vulnerability in the saveSettings() function caused by inadequate nonce verification. An attacker could exploit this flaw by crafting a malicious request that, if clicked by an administrator, would allow the attacker to change the plugin's configuration settings without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.