logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-36715

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-36715

Description:
The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4. This makes it possible for authenticated attackers to inject arbitrary web scripts into the plugin settings that execute if they can successfully trick a user into performing an action such as clicking on a link.
Last updated date:
06/12/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/12/2023
Reference url to background

https://blog.nintechnet.com/zero-day-vulnerability-fixed-in-wordpress-login-signup-popup-plugin/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy