VYPR
Unrated severityNVD Advisory· Published Sep 2, 2024· Updated Sep 3, 2024

DN Popup <= 1.2.2 - Settings Update via CSRF

CVE-2024-7690

Description

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

Affected products

2
  • WordPress/DN Popupdescription
  • DN/DN Popupllm-create
    Range: <=1.2.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.