Popup | Custom Popup Builder <= 1.3 - Denial of Service

2022-01-17 00:00
Felipe de Avila

Strategic Overview

Status
Patched in 1.3.1
Affected Version< 1.3.1
CVSS7.5High
CVECVE-2022-0214
View all Popup | Custom Popup Builder vulnerabilities

Vulnerability Overview

The Popup | Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

Technical Analysis

REMEDIATION: Update to version 1.3.1, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C