Input validation vulnerability in Popup Box – Create Countdown, Coupon, Video, Contact Form Popups 6.1.1

The Popup Box plugin for WordPress has a security issue that affects all versions up to 6.1.1. This is because the way it checks for a unique code is not secure. Instead of checking the code submitted in the request, it checks a code created by the plugin itself. This means that someone who is not logged in can manipulate the popups and change their status, as long as they can trick the site administrator into clicking a link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.