📦 Popup Builder

by Sygnoos

🔍 What is Popup Builder?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-0479

CRITICAL CVSS 9.8 Mar 28, 2022

This vulnerability in the Popup Builder WordPress plugin allows SQL injection and reflected XSS attacks. Attackers can exploit it by sending malicious links to logged-in administrators, potentially co...

CVE-2020-9006

CRITICAL CVSS 9.8 Feb 17, 2020

This vulnerability allows unauthenticated attackers to perform SQL injection via PHP deserialization in the Popup Builder WordPress plugin. Successful exploitation enables creation of WordPress admini...

CVE-2024-2544

HIGH CVSS 7.4 Jun 15, 2024

The Popup Builder WordPress plugin has a missing capability check on all AJAX actions, allowing authenticated attackers with subscriber-level access or higher to modify and delete data without authori...

CVE-2023-6294

HIGH CVSS 7.2 Feb 12, 2024

This vulnerability in the Popup Builder WordPress plugin allows administrators in Multisite WordPress configurations to perform Server-Side Request Forgery (SSRF) attacks. The plugin fails to validate...

CVE-2024-9428

MEDIUM CVSS 4.8 Dec 12, 2024

The Popup Builder WordPress plugin before version 4.3.5 contains a stored cross-site scripting (XSS) vulnerability in its settings. This allows authenticated administrators to inject malicious scripts...