Vulnerabilities > Xootix > Login Signup Popup > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-06 CVE-2024-5665 Missing Authorization vulnerability in Xootix Login/Signup Popup 2.7.1/2.7.2
The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ‘export_settings’ function in versions 2.7.1 to 2.7.2.
network
low complexity
xootix CWE-862
4.3
2023-06-07 CVE-2020-36715 Missing Authorization vulnerability in Xootix Login/Signup Popup
The Login/Signup Popup plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functions in versions up to, and including, 1.4.
network
low complexity
xootix CWE-862
4.6