Unauthorized Update of Plugin Settings Due to Missing Capability Check
CVE-2024-3602
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 June 2024
What is CVE-2024-3602?
The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers β Promolayer plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the disconnect_promolayer function in all versions up to, and including, 1.1.0. This makes it possible for authenticated attackers, with subscriber access or higher, to remove the Promolayer connection.
Affected Version(s)
Promolayer β Popup Builder & Abandonment Preventer 0 <= 1.1.0