The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
| Software | From | Fixed in |
|---|---|---|
| themehunk / wp_popup_builder | - | 1.2.9 |