CVE Database
/

CVE-2023-0772

Back to search

CVE-2023-0772

Published: Mar 13, 2023

Modified: Feb 27, 2025

PUBLISHED

Description

The Popup Builder by OptinMonster WordPress plugin before 2.12.2 does not ensure that the campaign to be loaded via some shortcodes is actually a campaign, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, like draft, private or even password protected ones.

VendorProductVersions

Unknown

Popup Builder by OptinMonster

affected
0 - < 2.12.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now