Sygnoos Popup Builder plugin <= 4.1.11 for WordPress contains a cross-site request forgery caused by lack of CSRF protection in plugin settings update, letting attackers change settings without authorization, exploit requires victim to visit malicious site or click malicious link.
id: CVE-2022-29495
info:
name: WordPress Popup Builder <= 4.1.11 - Cross-Site Request Forgery
a
...