CVE-2023-0766Cross-Site Request Forgery in Popup Project Newsletter Popup

Severity
8.8HIGHNVD
EPSS
0.1%
top 70.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 30

Description

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
Newsletter Popup <= 1.2 - Record Deletion via CSRF2023-05-30
GHSA
GHSA-fq23-cx8p-693x: The Newsletter Popup WordPress plugin through 12023-05-30
CVE-2023-0766 — Cross-Site Request Forgery | cvebase