PT-2024-28296 · WordPress · The Popup Box – Best Wordpress Popup Plugin

Krzysztof Zając

·

Published

2024-05-02

·

Updated

2024-05-02

·

CVE-2024-3897

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Popup Box – Best WordPress Popup Plugin versions prior to 4.3.7
Description The issue allows unauthorized access to data due to a missing capability check on the ays pb create author AJAX action. This makes it possible for unauthenticated attackers to enumerate all emails registered on the website.
Recommendations For versions up to and including 4.3.6, update to a version newer than 4.3.6 to resolve the issue. As a temporary workaround, consider restricting access to the ays pb create author AJAX action until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-3897

Affected Products

The Popup Box – Best Wordpress Popup Plugin