Vulnerabilities (CVE)

Filtered by vendor Sygnoos Subscribe
Filtered by product Popup Builder
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-9006 1 Sygnoos 1 Popup Builder 2021-07-21 7.5 HIGH 9.8 CRITICAL
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to possible Remote Code Execution because Administrators can run PHP code on Wordpress instances. (This issue has been fixed in the 3.x branch of popup-builder.)
CVE-2019-14695 1 Sygnoos 1 Popup Builder 2019-08-13 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.