CVE Database /
CVE-2024-3897
CVE · Medium
CVE-2024-3897 — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.3.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3897
|
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.3.7 |
Missing Authorization |
Medium
5.3
|
< 4.3.7
|
4.3.7 |
2024-04-24 |
—
|
CVE-2024-3897
The Popup Box plugin for WordPress contains a capability check vulnerability in the ays_pb_create_author AJAX action affecting versions through 4.3.6 that allows unauthenticated attackers to access sensitive data. Without proper authorization validation, an attacker can enumerate all email addresses registered on the affected WordPress site. The vulnerability was resolved in version 4.3.7.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings