CVE-2024-31421: WordPress Popup by Supsystic plugin <= 1.10.27 - Broken Access Control vulnerability
Published Apr 15, 2024
·Updated
Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.
Affected Software
3 affected components
Supsystic Popup Wordpress<1.10.28
Supsystic Popup<=1.10.27
WordPress Popup by Supsystic<=1.10.27
Remediation
Information
Update to 1.10.28 or a higher version.
Event History
Apr 15, 2024
CVE Published
via MITRE·10:09 AM
Data Sourced
via MITRE·10:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31421?
CVE-2024-31421 is classified as a missing authorization vulnerability in Supsystic Popup.
2
How do I fix CVE-2024-31421?
To fix CVE-2024-31421, update Supsystic Popup to version 1.10.28 or later.
3
What software is affected by CVE-2024-31421?
CVE-2024-31421 affects Popup by Supsystic versions up to and including 1.10.27.
4
What risks are associated with CVE-2024-31421?
The missing authorization vulnerability in CVE-2024-31421 may allow unauthorized access to sensitive functionalities.
5
Is there a known exploit for CVE-2024-31421?
Currently, no specific exploits for CVE-2024-31421 have been publicly disclosed.