CVE-2024-10861

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 16, 2024
CWE ID 862

Summary

CVE-2024-10861: A vulnerability affecting the Popup Box plugin for WordPress versions up to 4.9.7 allows unauthenticated attackers to modify plugin options. The issue stems from a missing capability check on the deactivate_plugin_option() function, enabling malicious actors to update the 'ays_pb_upgrade_plugin' option with arbitrary data. This vulnerability poses a significant risk, as it can lead to unintended plugin behavior or even complete plugin takeover. WordPress users are urged to update the plugin to the latest version to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share