First published: Fri Jul 22 2022(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sygnoos Popup Builder | <4.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-29495.
The title of the vulnerability is "Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress."
The severity of CVE-2022-29495 is medium with a severity value of 4.3.
CVE-2022-29495 affects the Sygnoos Popup Builder plugin version <= 4.1.11 at WordPress.
An attacker can exploit CVE-2022-29495 by performing a Cross-Site Request Forgery (CSRF) attack to update plugin settings.