momo安全漏洞库

多模块数据检索平台

登录 注册
返回列表

CVE-2022-29495: WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery

CVE: CVE-2022-29495
CNVD: 暂无
CNNVD: 暂无
漏洞类型: SQL注入
漏洞等级: 高危
年份: 2026
POC_ID: 暂无
漏洞描述
Sygnoos Popup Builder plugin <= 4.1.11 for WordPress contains a cross-site request forgery caused by lack of CSRF protection in plugin settings update, letting attackers change settings without authorization, exploit requires victim to visit malicious site or click malicious link. [已公开] id: CVE-2022-29495 info: name: WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery author: Shivam Kamboj severity: medium description: | Sygnoos Popup Builder plugin <= 4.1.11 for WordPress contains a cross-site request forgery caused by lack of CSRF protection in plugin settings update, letting attackers change settings without authorization, exploit requires victim to visit malicious site or click malicious link. impact: | Attackers can modify plugin settings without authorization, potentially leading to site defacement or malicious content injection. remediation: | Implement CSRF tokens and verify requests properly, update to the latest plugin version. reference: - https://nvd.nist.gov/vuln/detail/CVE-2022-29495 - https://patchstack.com/database/vulnerability/popup-builder/wordpress-popup-builder-plugin-4-1-11-cross-site-request-forgery-csrf-leading-to-plugin-settings-update metadata:
影响范围
未知
漏洞详情
登录后可查看漏洞详情。请先 登录注册
漏洞 POC
登录后可查看漏洞 POC。请先 登录注册
修复建议
暂无