← Back to CVE List

CVE-2022-0424

Published: 2022-05-09T17:15Z
Last Modified: 2024-11-21T06:38Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users > MITRE Terms of Use apply – see LICENSE‑MITRE.txt