Popup Maker <= 1.17.1 - Sensitive Data Exposure via debug log file
2023-03-14 00:00
rezadutyStrategic Overview
StatusPatched in 1.18.0
Affected PluginPopup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
Affected Version
<= 1.17.1CVSS5.3Medium
CVE
CVE-2022-47597Vulnerability Overview
The Popup Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.17.1 due to the fact that the plugin generates a predictable name when creating debug log files. This can allow unauthenticated attackers to view log files.
Technical Analysis
REMEDIATION: Update to version 1.18.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C