QID 150457

Date Published: 2022-01-27

QID 150457: WordPress Login/Signup Popup Plugin: CSRF Vulnerability (CVE-2022-0215)

Login/Signup Popup is a simple and light weight WordPress plugin which allow users to login/signup anywhere from the site with the simple pop up without refreshing page. Supported by Woocommerce.

In the installed version of the WordPress plugin, the "save_settings" function does not check for the "nonce", which could allow cross-site request forgery (CSRF) under some circumstances.

CSRF : Cross-site request forgery is a web security vulnerability that allows an attacker to induce users to perform actions that they do not intend to perform.

Affected Versions:
Login/Signup popup plugins before version 2.3

Successful exploitation of this vulnerability may allow remote attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to a fixed version Login/Signup Popup 2.3 or later versions to remediate this vulnerability.
    Please refer to Wordfence security blog.

    CVEs related to QID 150457

    Software Advisories
    Advisory ID Software Component Link
    Wordfence URL Logo www.wordfence.com/blog/2022/01/84000-wordpress-sites-affected-by-three-plugins-with-the-same-vulnerability/