Popup by Supsystic <= 1.10.8 - Sensitive Information Disclosure

2022-04-18 00:00
Felipe de Avila

Strategic Overview

Status
Patched in 1.10.9
Affected Version< 1.10.9
CVSS5.3Medium
CVECVE-2022-0424
View all Smart Popup by Supsystic vulnerabilities

Vulnerability Overview

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

Technical Analysis

REMEDIATION: Update to version 1.10.9, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C