CVE Database /
CVE-2024-2541
CVE · High
CVE-2024-2541 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-2541
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.7 |
Exposure of Sensitive Information to an Unauthorized Actor |
High
7.5
|
< 4.3.7
|
4.3.7 |
2024-08-28 |
—
|
CVE-2024-2541
The Popup Builder plugin before version 4.3.7 contains a sensitive information exposure flaw in its Subscribers Import functionality that allows unauthenticated attackers to access subscriber data following CSV file uploads by administrators. The vulnerability exposes personally identifiable information such as names, email addresses, and other subscriber details that were imported through the feature. This issue affects all versions through 4.3.3 and poses a risk to the privacy of individuals whose data has been imported into the system.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings