CVE-2023-46197
WordPress Popup by Supsystic plugin <= 1.10.19 - Unauthenticated Subscriber Email Addresses Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.
LimitaciĆ³n incorrecta de una vulnerabilidad de nombre de ruta a un directorio restringido ("Path Traversal") en supsystic.Com Popup de Supsystic permite un path traversal relativa. Este problema afecta a Popup de Supsystic: desde n/a hasta 1.10.19.
The Popup by Supsystic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.19 via the getWpCsvList action. This makes it possible for authenticated attackers with subscriber level access or higher to extract sensitive data including subscriber email addresses. CVE-2023-51353 appears to be a duplicate of this issue.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-10-18 CVE Reserved
- 2023-10-18 CVE Published
- 2023-10-23 First Exploit
- 2024-05-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
- CAPEC-139: Relative Path Traversal
References (2)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/popup-by-supsystic/wordpress-popup-by-supsystic-plugin-1-10-19-unauthenticated-subscriber-email-addresses-disclosure?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://github.com/RandomRobbieBF/CVE-2023-46197 | 2023-10-23 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Popup By Supsystic Search vendor "Popup By Supsystic" | Popup By Supsystic Search vendor "Popup By Supsystic" for product "Popup By Supsystic" | >= 0.0.0 <= 1.10.19 Search vendor "Popup By Supsystic" for product "Popup By Supsystic" and version " >= 0.0.0 <= 1.10.19" | en |
Affected
|