Description
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
Scores
CVSS v3
7.5
EPSS
0.0199
EPSS Percentile
83.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-1284
Status
published
Products (1)
custom_popup_builder_project/custom_popup_builder
< 1.3.1
Published
Feb 14, 2022
Tracked Since
Feb 18, 2026