CVE-2024-3477: Popup Box < 2.2.7 - Popup Deletion via CSRF
Published May 2, 2024
·Updated
The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks
Affected Software
2 affected components
Popup Box Popup Box WordPress plugin<2.2.7
Wow-Company Popup Box WordPress<2.2.7
Event History
May 2, 2024
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-3477?
CVE-2024-3477 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2024-3477?
To fix CVE-2024-3477, update the Popup Box WordPress plugin to version 2.2.7 or later.
3
What type of vulnerability is CVE-2024-3477?
CVE-2024-3477 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Who is affected by CVE-2024-3477?
Users with Popup Box WordPress plugin versions prior to 2.2.7 are affected by CVE-2024-3477.
5
What actions could attackers perform due to CVE-2024-3477?
Attackers could potentially make logged-in admins delete popups through CSRF attacks due to CVE-2024-3477.