The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-27T21:10:26.369Z
Reserved: 2023-02-10T11:01:27.992Z
Link: CVE-2023-0772

Updated: 2024-08-02T05:24:34.254Z

Status : Modified
Published: 2023-03-13T17:15:12.767
Modified: 2025-02-27T22:15:35.663
Link: CVE-2023-0772

No data.