PT-2022-7938 · WordPress · Supsystic Popup Plugin

Radjnies Bhansingh

·

Published

2022-06-20

·

Updated

2022-06-28

·

CVE-2017-20065

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Supsystic Popup Plugin version 1.7.6
Description A vulnerability was found in the Supsystic Popup Plugin, affecting some unknown processing, which leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Supsystic Popup Plugin version 1.7.6, update to a newer version to mitigate the risk of cross-site request forgery. As a temporary workaround, consider restricting access to the plugin until a patch is available.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20065

Affected Products

Supsystic Popup Plugin