Loading vulnerability details…
CVSS v3.1
4.3
EPSS
0.27%
Published
Dec 19, 2022
Modified
Apr 14, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The Popup Manager WordPress plugin through 1.6.6 does not have authorisation and CSRF checks when deleting popups, which could allow unauthenticated users to delete them
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NWeaknesses (CWE)
Affected Products (1)
References (2)