CVE-2022-32289: WordPress Popup Builder plugin <= 4.1.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Popup Status Change
Published Jul 21, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.
Affected Software
1 affected component
Sygnoos Popup Builder Wordpress<4.1.1
Remediation
Information
Update to 4.1.1 or higher version.
Event History
Jul 21, 2022
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this CSRF vulnerability?
The vulnerability ID of this CSRF vulnerability is CVE-2022-32289.
2
What is the affected software of this vulnerability?
The affected software of this vulnerability is Sygnoos Popup Builder plugin <= 4.1.0 at WordPress.
3
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 4.3.
4
How does this vulnerability affect WordPress?
This vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress can lead to popup status change due to CSRF attacks.
5
How can I fix this CSRF vulnerability?
To fix this CSRF vulnerability, update the Sygnoos Popup Builder plugin to version 4.1.1 or later.