Sygnoos

Popup Builder

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 76.37%
  • Veröffentlicht 28.03.2022 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:38:44

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to p...

Exploit
  • EPSS 4.16%
  • Veröffentlicht 21.02.2022 11:15:09
  • Zuletzt bearbeitet 21.11.2024 06:38:11

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

Exploit
  • EPSS 19.89%
  • Veröffentlicht 21.02.2022 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:54:18

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, ...

  • EPSS 0.21%
  • Veröffentlicht 05.04.2021 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:52:28

The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 13.03.2020 16:15:12
  • Zuletzt bearbeitet 07.05.2025 15:42:53

An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com/classes/Ajax.php. It is possible for an unauthenticated attac...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 13.03.2020 16:15:12
  • Zuletzt bearbeitet 07.05.2025 15:42:53

The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post...

Exploit
  • EPSS 41.25%
  • Veröffentlicht 17.02.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:39:49

The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows cr...

  • EPSS 1.39%
  • Veröffentlicht 06.08.2019 14:15:12
  • Zuletzt bearbeitet 21.11.2024 04:27:09

A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Tabl...