Information Disclosure and Settings Modification in Popup Builder Plugin for WordPress
CVE-2020-10195
6.3MEDIUM
What is CVE-2020-10195?
The Popup Builder Plugin for WordPress prior to version 3.64.1 is susceptible to critical security vulnerabilities that allow authenticated users with minimal permissions (such as subscribers) to execute administrative actions. By manipulating the action parameter through the POST requests sent to wp-admin/admin-post.php, attackers can modify plugin settings, which may grant unauthorized roles access to sensitive functionalities. Additionally, they can export a list of newsletter subscribers and extract system configuration details, including the web server configuration and a list of installed plugins, leading to potential data breaches and privilege escalation.