CVE-2022-29495: WordPress Popup Builder plugin <= 4.1.11 - Cross-Site Request Forgery (CSRF) leading to plugin settings update
Published Jul 22, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
Affected Software
1 affected component
Sygnoos Popup Builder Wordpress<4.1.12
Remediation
Information
Update to 4.1.12 or higher version.
Event History
Jul 22, 2022
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-29495.
2
What is the title of the vulnerability?
The title of the vulnerability is "Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress."
3
What is the severity of CVE-2022-29495?
The severity of CVE-2022-29495 is medium with a severity value of 4.3.
4
What does CVE-2022-29495 affect?
CVE-2022-29495 affects the Sygnoos Popup Builder plugin version <= 4.1.11 at WordPress.
5
How can an attacker exploit CVE-2022-29495?
An attacker can exploit CVE-2022-29495 by performing a Cross-Site Request Forgery (CSRF) attack to update plugin settings.