CVE-2024-3643: Newsletter Popup <= 1.2 - List Deletion via CSRF
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3643?
CVE-2024-3643 is classified as a medium severity vulnerability due to its potential for CSRF attacks against logged-in admins.
How do I fix CVE-2024-3643?
To fix CVE-2024-3643, update the Newsletter Popup WordPress plugin to a version higher than 1.2 that implements CSRF protections.
What does CVE-2024-3643 affect?
CVE-2024-3643 affects the Newsletter Popup WordPress plugin versions up to and including 1.2.
What kind of attack is CVE-2024-3643 related to?
CVE-2024-3643 is related to Cross-Site Request Forgery (CSRF) attacks that can target logged-in administrators.
Who is at risk from CVE-2024-3643?
Users who have installed the vulnerable versions of the Newsletter Popup plugin and have admin roles are at risk from CVE-2024-3643.