CVE-2022-38070: WordPress Pop-up plugin <= 1.1.5 - Privilege Escalation vulnerability
Published Sep 9, 2022
·Updated
Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
Affected Software
1 affected component
Mypopups Pop-up Wordpress<=1.1.5
Remediation
Information
Update to 1.1.6 or higher version.
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Privilege Escalation vulnerability?
The vulnerability ID for this Privilege Escalation vulnerability is CVE-2022-38070.
2
What is the severity of CVE-2022-38070?
The severity of CVE-2022-38070 is high with a CVSS score of 8.8.
3
What is the affected software for CVE-2022-38070?
The affected software for CVE-2022-38070 is the Pop-up plugin <= 1.1.5 at WordPress.
4
How does CVE-2022-38070 work?
CVE-2022-38070 is a Privilege Escalation vulnerability that allows subscribers or higher privileged users to escalate their privileges and gain unauthorized access to sensitive information or perform malicious actions.
5
How do I fix CVE-2022-38070?
To fix CVE-2022-38070, update the Pop-up plugin to a version higher than 1.1.5 or remove the plugin if it's not necessary for your website.