CVE · Medium

CVE-2024-10861 — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.9.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10861 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.9.8 Missing Authorization Medium 5.3 < 4.9.8 4.9.8 2024-11-15

CVE-2024-10861

The Popup Box plugin for WordPress contained a capability check vulnerability in its deactivate_plugin_option() function through version 4.9.7, allowing unauthenticated users to arbitrarily modify the 'ays_pb_upgrade_plugin' option. This flaw enabled unauthorized attackers to update plugin settings without proper authentication or authorization. The vulnerability was resolved in version 4.9.8.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.