Beveiligingsadvies

CVE-2023-6294

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-02-12 16:06:01
Laatst bijgewerkt 2025-04-24 15:43:33
Toegewezen door WPScan
CVSS-score 7.5
Status PUBLISHED

Beschrijving

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.