Vulnerability Description
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Custom Popup Builder Project | Custom Popup Builder | < 1.3.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/ca2e8feb-15d6-4965-ad9c-8da1bc01e0f4ExploitThird Party Advisory
- https://wpscan.com/vulnerability/ca2e8feb-15d6-4965-ad9c-8da1bc01e0f4ExploitThird Party Advisory
FAQ
What is CVE-2022-0214?
CVE-2022-0214 is a vulnerability with a CVSS score of 7.5 (HIGH). The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a...
How severe is CVE-2022-0214?
CVE-2022-0214 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0214?
Check the references section above for vendor advisories and patch information. Affected products include: Custom Popup Builder Project Custom Popup Builder.