CVE-2024-10861: Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update
The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivatepluginoption() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ayspbupgradeplugin' option with arbitrary data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2024-10861?
CVE-2024-10861 is a vulnerability in the Popup Box plugin for WordPress that allows unauthorized modification of data due to a missing capability check.
What versions of the Popup Box plugin are affected by CVE-2024-10861?
CVE-2024-10861 affects all versions of the Popup Box plugin up to and including version 4.9.7.
How do I fix CVE-2024-10861?
To fix CVE-2024-10861, you should update the Popup Box plugin to version 4.9.8 or later, which addresses this vulnerability.
What are the risks of CVE-2024-10861 for my WordPress site?
The risks of CVE-2024-10861 include potential unauthorized data modification that could compromise the security of your WordPress site.
How can I determine if I am using a vulnerable version relating to CVE-2024-10861?
You can determine if you are using a vulnerable version by checking your Popup Box plugin version against the affected versions list which includes all versions up to 4.9.7.