Popup | Custom Popup Builder <= 1.3 - Denial of Service
2022-01-17 00:00
Felipe de AvilaStrategic Overview
StatusPatched in 1.3.1
Affected PluginPopup | Custom Popup Builder
Affected Version
< 1.3.1CVSS7.5High
CVE
CVE-2022-0214Vulnerability Overview
The Popup | Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
Technical Analysis
REMEDIATION: Update to version 1.3.1, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C