CVE-2024-2541: Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File
The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an administrator has imported subscribers via a CSV file. This data may include the first name, last name, e-mail address, and potentially other personally identifiable information of subscribers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2541?
CVE-2024-2541 is classified as a critical vulnerability due to its potential for unauthenticated access to sensitive information.
How do I fix CVE-2024-2541?
To mitigate CVE-2024-2541, update the Popup Builder plugin for WordPress to version 4.3.4 or later.
What data is exposed in CVE-2024-2541?
CVE-2024-2541 can expose sensitive information related to subscribers through the Subscribers Import feature.
Who is affected by CVE-2024-2541?
All users of the Popup Builder plugin for WordPress versions up to and including 4.3.3 are affected by CVE-2024-2541.
Is authentication required to exploit CVE-2024-2541?
No, CVE-2024-2541 can be exploited by unauthenticated attackers.