CVE-2022-0479
- EPSS 76.37%
- Veröffentlicht 28.03.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:44
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to p...
CVE-2022-0228
- EPSS 4.16%
- Veröffentlicht 21.02.2022 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:38:11
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection
CVE-2021-25082
- EPSS 19.89%
- Veröffentlicht 21.02.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 05:54:18
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, ...
CVE-2021-24152
- EPSS 0.21%
- Veröffentlicht 05.04.2021 19:15:14
- Zuletzt bearbeitet 21.11.2024 05:52:28
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
CVE-2020-10196
- EPSS 0.23%
- Veröffentlicht 13.03.2020 16:15:12
- Zuletzt bearbeitet 07.05.2025 15:42:53
An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com/classes/Ajax.php. It is possible for an unauthenticated attac...
CVE-2020-10195
- EPSS 0.46%
- Veröffentlicht 13.03.2020 16:15:12
- Zuletzt bearbeitet 07.05.2025 15:42:53
The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post...
CVE-2020-9006
- EPSS 41.25%
- Veröffentlicht 17.02.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:49
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows cr...
CVE-2019-14695
- EPSS 1.39%
- Veröffentlicht 06.08.2019 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:27:09
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Tabl...