Claspo Popup Builder Missing Authorization Vulnerability in WordPress
Vulnerability
A missing authorization vulnerability has been identified in the Claspo Popup Builder WordPress plugin, specifically in versions through 1.0.5. This vulnerability arises from incorrectly configured access control security levels, allowing unauthorized exploitation.
Impact
Exploitation of this vulnerability could lead to unauthorized access or manipulation of features within the Popup Builder, such as Exit-Intent pop-ups, Spin the Wheel promotions, Newsletter sign-up forms, Email Capture, and Lead Generation forms.
Added: Dec 24, 2025, 2:07 PM
Updated: Dec 24, 2025, 9:08 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
6.6remediation
0.0relevance
1.7threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
