CVE · Medium

CVE-2024-3897 — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.3.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3897 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.3.7 Missing Authorization Medium 5.3 < 4.3.7 4.3.7 2024-04-24

CVE-2024-3897

The Popup Box plugin for WordPress contains a capability check vulnerability in the ays_pb_create_author AJAX action affecting versions through 4.3.6 that allows unauthenticated attackers to access sensitive data. Without proper authorization validation, an attacker can enumerate all email addresses registered on the affected WordPress site. The vulnerability was resolved in version 4.3.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.