Login/Signup Popup < 1.5 - Missing Authorization
2020-05-14 00:00
Jerome BruandetStrategic Overview
StatusPatched in 1.5
Affected Version
< 1.5CVSS7.4High
CVE
CVE-2020-36715Vulnerability Overview
The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can successfully trick a user into performing an action such as clicking on a link.
Technical Analysis
REMEDIATION: Update to version 1.5, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C