CVE Database /
CVE-2024-34367
CVE · High
CVE-2024-34367 — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.1.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-34367
|
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.1.3 |
Cross-Site Request Forgery (CSRF) |
High
7.1
|
< 4.1.3
|
4.1.3 |
2024-05-03 |
—
|
CVE-2024-34367
The Popup Box plugin contains a Cross-Site Request Forgery vulnerability affecting versions 4.1.2 and earlier due to inadequate nonce verification in certain functions. An unauthenticated attacker can exploit this flaw to inject malicious scripts if they can deceive a site administrator into clicking a crafted link. The vulnerability was resolved in version 4.1.3.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings