Cross-Site Request Forgery in Advanced Popups Plugin for WordPress
CVE-2021-4421
4.3MEDIUM
What is CVE-2021-4421?
The Advanced Popups plugin for WordPress contains a vulnerability that can be exploited through Cross-Site Request Forgery (CSRF) due to inadequate nonce validation in the metabox_popup_save() function. This security flaw permits unauthorized attackers to manipulate site functionalities by tricking a site administrator into executing a malicious action, such as clicking on a specially crafted link. The issue exists in versions up to and including 1.1.1, highlighting the importance of ensuring all plugins are updated to maintain site integrity.
Affected Version(s)
Advanced Popups 0 <= 1.1.1