First published: Wed Mar 29 2023(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Essentialplugin Popup Anything | <=2.2.1 |
Update to 2.2.2 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38077 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
To remediate CVE-2022-38077, update the Essential Plugin Popup Anything to version 2.2.2 or later.
CVE-2022-38077 affects the Essential Plugin Popup Anything versions up to and including 2.2.1.
CVE-2022-38077 can allow an attacker to perform unauthorized actions on behalf of authenticated users due to CSRF.
Additional details about CVE-2022-38077 can be found in security advisories related to the Essential Plugin Popup Anything.