WordPress BBS e-Popup plugin <= 2.4.5 - Broken Access Control vulnerability
CVE-2023-36504
9.8CRITICAL
What is CVE-2023-36504?
A vulnerability in BBS e-Theme's BBS e-Popup plugin has been identified, characterized by a missing authorization mechanism. This issue allows unauthorized users to execute actions that should be restricted, potentially compromising user data and system integrity. The attack window affects versions from n/a up to 2.4.5, necessitating prompt attention from website operators using this plugin to mitigate risks and enhance security measures.
Affected Version(s)
BBS e-Popup <= 2.4.5