1 results (0.001 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

23 Jun 2023 — Missing Authorization vulnerability in BBS e-Theme BBS e-Popup.This issue affects BBS e-Popup: from n/a through 2.4.5. Vulnerabilidad de autorización faltante en BBS e-Theme BBS e-Popup. Este problema afecta a BBS e-Popup: desde n/a hasta 2.4.5. The BBS e-Popup plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bbse_popup_admin_action_proc() function called via admin_action in versions up to, and including, 2.4.5. This makes it possible for unaut... • https://patchstack.com/database/vulnerability/bbs-e-popup/wordpress-bbs-e-popup-plugin-2-4-5-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •