CVE-2025-68568
Missing Authorization in Popup Builder β€1.0.5 Enables Access Bypass
Publication date: 2025-12-24
Last updated on: 2026-04-27
Assigner: Patchstack
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| claspo | popup_builder | 1.0.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Missing Authorization issue in the Popup Builder plugin by integrationclaspo. It affects features like Exit-Intent pop-up, Spin the Wheel, Newsletter signup, Email Capture, and Lead Generation forms. The problem arises from incorrectly configured access control security levels, which means unauthorized users might exploit the plugin due to insufficient authorization checks.
How can this vulnerability impact me? :
The impact of this vulnerability could include unauthorized access or manipulation of popup and lead generation features, potentially allowing attackers to bypass security controls and exploit the plugin's functionalities for malicious purposes.