{"error":0,"message":null,"data":{"name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups.","plugin":"popup-builder","link":"https:\/\/wordpress.org\/plugins\/popup-builder\/","latest":"1784361600","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"d27b28d3a2c0f8aa49c8c5d09067d845c987422791b04499c8a607e5dd7dbd8d","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0228","name":"CVE-2022-0228","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0228","description":"[en] The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection","date":"2022-02-21"},{"id":"dc6f45ccbacfd83dfecf13a8bad6407433d6de0a","name":"WordPress Popup Builder plugin <= 4.0.6 - SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-0-6-sql-injection-sqli-vulnerability","description":"SQL Injection (SQLi) vulnerability discovered in WordPress Popup Builder plugin (versions <= 4.0.6).","date":"2022-01-24"},{"id":"b84f2d780a582f3b5cebb8a4aa163a3364aed18d","name":"Popup Builder <= 4.0.6 - Authenticated SQL Injection via order & orderby Parameters","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-406-authenticated-sql-injection-via-order-orderby-parameters","description":"The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection","date":"2022-01-24"},{"id":"22facac2-52f4-4e5f-be59-1d2934b260d9","name":"Popup Builder &lt; 4.0.7 - Admin+ SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/22facac2-52f4-4e5f-be59-1d2934b260d9","description":"The plugin does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"c6bc06fc6e2bf3edfa4f5c9624bde7e6ec20174e0e669b8e42efd8a751230e18","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-25082","name":"CVE-2021-25082","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-25082","description":"[en] The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR","date":"2022-02-21"},{"id":"4e7fb44b62b150e8eef1880732e3757a9ef8c739","name":"WordPress Popup Builder plugin <= 4.0.6 - Local File Inclusion (LFI) leading to Remote Code Execution (RCE)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-0-6-local-file-inclusion-lfi-leading-to-remote-code-execution-rce","description":"Local File Inclusion (LFI) leading to Remote Code Execution (RCE) discovered by JrXnm in WordPress Popup Builder plugin (versions <= 4.0.6).","date":"2022-01-24"},{"id":"e33846c09a15499a4a7e8b1b28a0ae5622cbe4ec","name":"Popup Builder <= 4.0.6 - Local File Inclusion and PHAR Deserialization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-406-local-file-inclusion-and-phar-deserialization","description":"The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR","date":"2022-01-24"},{"id":"0f90f10c-4b0a-46da-ac1f-aa6a03312132","name":"Popup Builder &lt; 4.0.7 - LFI to RCE","link":"https:\/\/wpscan.com\/vulnerability\/0f90f10c-4b0a-46da-ac1f-aa6a03312132","description":"The plugin does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR","date":null},{"id":"EUVD-2021-11994","name":"EUVD-2021-11994","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2021-11994","description":"Malicious code in bioql (PyPI)","date":"2025-10-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"epss":"0.012"}},{"uuid":"ec009ea24cebba34af662c1ecd394721cb362fcafb8be0291178b3b01e3f5f17","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.74","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.74","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24152","name":"CVE-2021-24152","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24152","description":"[en] The \"All Subscribers\" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.","date":"2021-04-05"},{"id":"59cb7316c5c3e880d973e78d91632deb160dfbda","name":"Popup Builder <= 3.73 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-373-reflected-cross-site-scripting","description":"The \"All Subscribers\" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.","date":"2021-02-02"},{"id":"597e9686-f4e2-43bf-85ef-c5967e5652bd","name":"Popup Builder &lt; 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/597e9686-f4e2-43bf-85ef-c5967e5652bd","description":"The &quot;All Subscribers&quot; setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"e399df730bf5799f64399a637a29439e56b5820ea629499309fac91aec633fa0","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.64.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-10195","name":"CVE-2020-10195","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-10195","description":"[en] The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com\/classes\/Actions.php. By sending a POST request to wp-admin\/admin-post.php, an authenticated attacker with minimal (subscriber-level) permissions can modify the plugin's settings to allow arbitrary roles (including subscribers) access to plugin functionality by setting the action parameter to sgpbSaveSettings, export a list of current newsletter subscribers by setting the action parameter to csv_file, or obtain system configuration information including webserver configuration and a list of installed plugins by setting the action parameter to sgpb_system_info.","date":"2020-03-13"},{"id":"4bf8e421bce15859df7486dd45dde66eb9541c60","name":"Popup Builder <= 3.63 - Authenticated Settings Modification, Configuration Disclosure, and User Data Export","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-363-authenticated-settings-modification-configuration-disclosure-and-user-data-export","description":"The Popup Builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com\/classes\/Actions.php. By sending a POST request to wp-admin\/admin-post.php, an authenticated attacker with minimal (subscriber-level) permissions can modify the plugin's settings to allow arbitrary roles (including subscribers) access to plugin functionality by setting the action parameter to sgpbSaveSettings, export a list of current newsletter subscribers by setting the action parameter to csv_file, or obtain system configuration information including webserver configuration and a list of installed plugins by setting the action parameter to sgpb_system_info.","date":"2020-03-12"},{"id":"d2df1d73-ed0f-4911-b827-998384f937b4","name":"Popup Builder &lt; 3.64.1 - Multiple Issues","link":"https:\/\/wpscan.com\/vulnerability\/d2df1d73-ed0f-4911-b827-998384f937b4","description":"&quot;One vulnerability allowed an unauthenticated attacker to inject malicious JavaScript into any published popup, which would then be executed whenever the popup loaded. The other vulnerability allowed any logged-in user, even those with minimal permissions such as a subscriber, to export a list of all newsletter subscribers, export system configuration information, and grant themselves access to various features of the plugin.&quot;\r\n\r\n- Unauthenticated Stored Cross-Site Scripting (XSS)\r\n- Authenticated Settings Modification, Configuration Disclosure, and User Data Export","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"6.3","severity":"m","exploitable":"2.8","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"6.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"3.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"0e42744b5dea6a1ac8267fd9cd26fadeb26e889a61aff4790d1a99354331732c","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.64.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-10196","name":"CVE-2020-10196","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-10196","description":"[en] An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com\/classes\/Ajax.php. It is possible for an unauthenticated attacker to insert malicious JavaScript in several of the popup's fields by sending a request to wp-admin\/admin-ajax.php with the POST action parameter of sgpb_autosave and including additional data in an allPopupData parameter, including the popup's ID (which is visible in the source of the page in which the popup is inserted) and arbitrary JavaScript which will then be executed in the browsers of visitors to that page. Because the plugin functionality automatically adds script tags to data entered into these fields, this injection will typically bypass most WAF applications.","date":"2020-03-13"},{"id":"3d60308ffcbab75fdf8997762fc652fbd86d7cd8","name":"Popup Builder <= 3.63 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-363-unauthenticated-stored-cross-site-scripting","description":"An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com\/classes\/Ajax.php. It is possible for an unauthenticated attacker to insert malicious JavaScript in several of the popup's fields by sending a request to wp-admin\/admin-ajax.php with the POST action parameter of sgpb_autosave and including additional data in an allPopupData parameter, including the popup's ID (which is visible in the source of the page in which the popup is inserted) and arbitrary JavaScript which will then be executed in the browsers of visitors to that page. Because the plugin functionality automatically adds script tags to data entered into these fields, this injection will typically bypass most WAF applications.","date":"2020-03-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"d97b8cd37d584766574a29e7e7faa3ffdf749885957fb30dc39ded1bd97bae7a","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-9006","name":"CVE-2020-9006","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-9006","description":"[en] The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to possible Remote Code Execution because Administrators can run PHP code on Wordpress instances. (This issue has been fixed in the 3.x branch of popup-builder.)","date":"2020-02-17"},{"id":"6a68e3343c656ba1d76c4ce9cc56f1b2805ed1d7","name":"WordPress Popup Builder plugin <= 2.6.7.6 - SQL injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-2-6-7-6-sql-injection-sqli-vulnerability","description":"SQL injection (SQLi) vulnerability discovered by ZeroAuth in WordPress Popup Builder plugin (versions <= 2.6.7.6).","date":"2020-02-16"},{"id":"78bd180a473cbf827858ae74df5955404bb7e982","name":"Popup Builder 2.2.8 - 2.6.7.6 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-228-2676-php-object-injection","description":"The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to possible Remote Code Execution because Administrators can run PHP code on Wordpress instances. (This issue has been fixed in the 3.x branch of popup-builder.)","date":"2020-02-16"},{"id":"2ab5c75b-b390-4aa6-aa0b-c1d4e1e3e737","name":"Popup Builder &lt; 3.0 - SQL injection via PHP Deserialization","link":"https:\/\/wpscan.com\/vulnerability\/2ab5c75b-b390-4aa6-aa0b-c1d4e1e3e737","description":"The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to possible Remote Code Execution because Administrators can run PHP code on WordPress instances.\r\n\r\nThis issue has been fixed in the 3.x branch of popup-builder. Versions 2.2.8 through 2.5.3 do not need a nonce, however 2.5.4 through 2.6.7.6 would need a valid nonce.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."},{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}]}},{"uuid":"8c62f2fc895699ee4eaabefe751b84f16882b22bf8617b8b83aa822846753aa2","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.45","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-14695","name":"CVE-2019-14695","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-14695","description":"[en] A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com\/libs\/Table.php because Subscribers Table ordering is mishandled.","date":"2019-08-06"},{"id":"4044d06c7ea86e1d6baa74dbc1624e376436d6e8","name":"Popup Builder <= 3.44 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-344-sql-injection","description":"A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com\/libs\/Table.php because Subscribers Table ordering is mishandled.","date":"2019-08-06"},{"id":"6de2c4fc-2b0d-427e-8108-5503659f6ba2","name":"Popup Builder &lt;= 3.44 - SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/6de2c4fc-2b0d-427e-8108-5503659f6ba2","description":"The Popup Builder &ndash; Responsive WordPress Pop up &ndash; Subscription &amp; Newsletter WordPress plugin was affected by a SQL Injection security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"79fcbac9530fa787035340a2a9677898520f08e3bbf53a0ebb7d66b81ea8d688","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-0479","name":"CVE-2022-0479","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-0479","description":"[en] The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link","date":"2022-03-28"},{"id":"9d190846d6b5694e715933272e91ea6b2f708a53","name":"WordPress Popup Builder plugin <= 4.1.0 - SQL Injection (SQLi) vulnerability to Reflected Cross-Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-1-0-sql-injection-sqli-vulnerability-to-reflected-cross-site-scripting-xss","description":"SQL Injection (SQLi) vulnerability to Reflected Cross-Site Scripting (XSS) discovered by Krzysztof Zaj\u0105c in WordPress Popup Builder plugin (versions <= 4.1.0).","date":"2022-03-07"},{"id":"3fdc9b4ecfe9df8a12afec0aae41c1fb07453978","name":"Popup Builder <= 4.1.0 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-410-sql-injection","description":"The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link","date":"2022-03-07"},{"id":"0d2bbbaf-fbfd-4921-ba4e-684e2e77e816","name":"Popup Builder &lt; 4.1.1 - SQL Injection to Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/0d2bbbaf-fbfd-4921-ba4e-684e2e77e816","description":"The plugin does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"b393cddd1f1f4ef92f8676c9ec869c579c4b2dcaf6cd84c8d09f621ec709806e","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.72","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7856a1f0732684268bcb4eb4c391f3ee725c35f6","name":"WordPress Popup Builder plugin <= 3.71 - Authenticated Local File Inclusion (LFI) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-3-71-local-file-inclusion-lfi-vulnerability","description":"Authenticated Local File Inclusion (LFI) vulnerability found by Dave Jong (WebARX Security) in WordPress Popup Builder plugin (versions <= 3.71).","date":"2021-01-28"}],"impact":[]},{"uuid":"d0637789e90a724fe3f3c5980e4cd66d5bc988cc49e43bdbcc06ea9c90830b77","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.72","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dfc0399ff12881910d936e91e9be6de6efb5d081","name":"WordPress Popup Builder plugin <= 3.71 - Authenticated Deleting\/Importing Subscribers vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-3-71-deleting-importing-subscribers-vulnerability","description":"Authenticated Deleting\/Importing Subscribers vulnerability found by Dave Jong (WebARX Security) in WordPress Popup Builder plugin (versions <= 3.71).","date":"2021-01-28"}],"impact":[]},{"uuid":"695604e75b45c6d68296d261f4588e83ba62d01d3dd4fe5d278c3907f04e6492","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.72","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"471621d7bcf76ab7c1532b39c38be248f6a1bdd5","name":"WordPress Popup Builder plugin <= 3.71 - Authenticated Newsletter Send With Custom Content And Sender vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-3-71-authenticated-newsletter-send-with-custom-content-and-sender-vulnerability","description":"Authenticated Newsletter Send With Custom Content And Sender vulnerability found by Dave Jong (WebARX Security) in WordPress Popup Builder plugin (versions <= 3.71).","date":"2021-01-28"}],"impact":[]},{"uuid":"ffb3e4eaeeb0c50051e1bbfd536e54b56c5d0e07037c601c584cc4f0e9cb8b6d","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.69.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.69.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c281f424cbc69357fce74b88f4aa31996527a753","name":"WordPress Popup Builder plugin <= 3.69.6 - Multiple Stored Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-3-69-6-multiple-stored-cross-site-scripting-xss-vulnerabilities","description":"Multiple Stored Cross-Site Scripting (XSS) vulnerabilities were found by Ilca Lucian Florin in the WordPress Popup Builder plugin (versions <= 3.69.6).","date":"2020-12-14"}],"impact":[]},{"uuid":"73f4c5a37dc19b0b3430c5104c2dd38d8637de38cff266a660e5ab3ae0a40432","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.45","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"93cda31b0d04697d97e17a235929701e3a4e04fe","name":"WordPress Popup Builder plugin <= 3.44 - SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-3-44-sql-injection-sqli-vulnerability","description":"SQL Injection (SQLi) vulnerability found by Tin Duong (Fortinet FortiGuard Labs) in WordPress Popup Builder plugin (versions <= 3.44).","date":"2019-08-06"}],"impact":[]},{"uuid":"b570836fa9610f66b3797a2698a13c7b877778a8073352a92d970df3fb437b97","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-32289","name":"CVE-2022-32289","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-32289","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.","date":"2022-07-21"},{"id":"902aa9441bbee8d33aabc40cbdec5b39460d48c8","name":"WordPress Popup Builder plugin <= 4.1.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Popup Status Change","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-1-0-cross-site-request-forgery-csrf-vulnerability-leading-to-popup-status-change","description":"Cross-Site Request Forgery (CSRF) vulnerability leading to Popup Status Change discovered by BEE-K (Patchstack) in WordPress Popup Builder plugin (versions <= 4.1.0).\nUpdate the WordPress Popup Builder plugin to the latest available version (at least 4.1.1).","date":"2022-06-17"},{"id":"8f0e8fe1482a98a4901cee703ccce05d0ace8e4d","name":"Popup Builder <= 4.1.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-410-cross-site-request-forgery","description":"The Popup Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing nonce validation on thechangePopupStatus() function. This makes it possible for unauthenticated attackers to change a popup's status via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-06-17"},{"id":"f0e39557-fe07-4df0-8cc3-4d292f1f545d","name":"Popup Builder &lt; 4.1.1 - Popup Status Change via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/f0e39557-fe07-4df0-8cc3-4d292f1f545d","description":"The plugin does not have CSRF check in place when updating Popup status, which could allow attackers to make a logged in admin update them via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a41642a9844947eafb5efbddca97e11949297b6d40ad4b5dabfb70772e5adde9","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1894","name":"CVE-2022-1894","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1894","description":"[en] The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed","date":"2022-07-11"},{"id":"aba1b9c9669c6ab4bbe8a3f9000243023f597332","name":"WordPress Popup Builder plugin <= 4.1.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-1-10-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Pritam Dash in WordPress Popup Builder plugin (versions <= 4.1.10).\nUpdate the WordPress Popup Builder plugin to the latest available version (at least 4.1.11).","date":"2022-06-20"},{"id":"c184d7e482e906b5bcb715d7e11232e0cf9d06a4","name":"Popup Builder <= 4.1.10 - Authenticated (Admin+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-4110-authenticated-admin-cross-site-scripting","description":"The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html is disabled.","date":"2022-06-20"},{"id":"68af14ef-ca66-40d6-a1e5-09f74e2cd971","name":"Popup Builder &lt; 4.1.11 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/68af14ef-ca66-40d6-a1e5-09f74e2cd971","description":"The plugin does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"bb3c3a0a91ba54c9ca6c54d126bf9be2344ae216a6669e25cbb954aeccf0732e","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-29495","name":"CVE-2022-29495","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-29495","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.","date":"2022-07-22"},{"id":"ccee27f78436a40c3d23ccfb3a3d604ee22a980f","name":"WordPress Popup Builder plugin <= 4.1.11 - Cross-Site Request Forgery (CSRF) leading to plugin settings update","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-1-11-cross-site-request-forgery-csrf-leading-to-plugin-settings-update","description":"Cross-Site Request Forgery (CSRF) leading to plugin settings update discovered by Rafie Muhammad (Yeraisci) in WordPress Popup Builder plugin (versions <= 4.1.11).\nUpdate the WordPress Popup Builder plugin to the latest available version (at least 4.1.12).","date":"2022-06-30"},{"id":"40aa36008cb3a0637ca8cbcc89c074208776d1ca","name":"Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. <= 4.1.11 - Cross-Site Request Forgery to Settings Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-create-highly-converting-mobile-friendly-marketing-popups-4111-cross-site-request-forgery-to-settings-update","description":"The  \"Popup Builder \u2013 Create highly converting, mobile friendly marketing popups.\" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.11. This is due to missing or incorrect nonce validation on the saveSettings() function. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2022-06-30"},{"id":"ca0f90ef-af9a-4628-9032-b536a0e6cd9b","name":"Popup Builder &lt; 4.1.12 - Settings Update via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/ca0f90ef-af9a-4628-9032-b536a0e6cd9b","description":"The plugin does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"32a0f1efa395c9697af8492a0e824839cf4e81a02fcb18982193947034ee769c","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.72","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1fddd2cc6db091b10673f9c942951239e805729d","name":"Popup Builder <= 3.72 Missing Authorization on AJAX actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-372-missing-authorization-on-ajax-actions","description":"The Popup Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.71 due to missing capability checks on various actions called via AJAX. This makes it possible for attackers to import subscribers and send newsletters among other actions.","date":"2021-01-28"}],"impact":[]},{"uuid":"e0a425e25727ef5afdcf7f5df41943b2993b5468868945b6920ef81216ba29ae","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-3226","name":"CVE-2023-3226","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-3226","description":"[en] The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2023-09-25"},{"id":"29d3dac693410de2cbdb53bb42e526e504d30b91","name":"Popup Builder <= 4.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-4115-authenticated-admin-stored-cross-site-scripting","description":"The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2023-08-28"},{"id":"941a9aa7-f4b2-474a-84d9-9a74c99079e2","name":"Popup Builder &lt;= 4.1.15 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/941a9aa7-f4b2-474a-84d9-9a74c99079e2","description":"The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).\r\n\r\nNote: The vendor was made aware of the issue on June 14 and 28, 2023","date":null},{"id":"e6bac8d955d0f56b3e68fddbd4a3f880c57c8b2b","name":"WordPress  Popup Builder Plugin  <= 4.1.15 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-1-15-admin-stored-cross-site-scripting-vulnerability","description":"No patched version available.\nDipak Panchal (th3.d1pak) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Popup Builder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has not been known to be fixed yet.","date":"2023-09-26"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f47a7bfc6452b278bbf438c76d51955dc50e6ecb933ee1a69a09766a018d234a","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6000","name":"CVE-2023-6000","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6000","description":"[en] The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.","date":"2024-01-01"},{"id":"20b016953ba8419fc7b94e679d9196aad9fa9b59","name":"WordPress  Popup Builder Plugin  < 4.2.3 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-2-3-unauthenticated-stored-xss-vulnerability","description":"Update the WordPress Popup Builder plugin to the latest available version (at least 4.2.3).\nMarc Montpas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Popup Builder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.2.3.","date":"2023-12-12"},{"id":"a504a9767a3aaf994fbf3ef0653af968914a6d17","name":"Popup Builder <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-422-unauthenticated-stored-cross-site-scripting","description":"The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popups in versions up to 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-11"},{"id":"cdb3a8bd-4ee0-4ce0-9029-0490273bcfc8","name":"Popup Builder &lt; 4.2.3 - Unauthenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/cdb3a8bd-4ee0-4ce0-9029-0490273bcfc8","description":"The plugin does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"19b2bd0b4b0825c3b9379f2b05370916ce6d04e5dee3d41aeef76a67c263ab06","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6294","name":"CVE-2023-6294","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6294","description":"[en] The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.","date":"2024-02-12"},{"id":"efe26b58ee9d6f926834faf3a5f0812e1fc108cd","name":"WordPress  Popup Builder Plugin  < 4.2.6 is vulnerable to Server Side Request Forgery (SSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-2-6-admin-ssrf-file-read-vulnerability","description":"Update the WordPress Popup Builder plugin to the latest available version (at least 4.2.6).\nSebastian Neef discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Popup Builder Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information of other services running on the system. This vulnerability has been fixed in version 4.2.6.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"43acbfd45aaea7160f67d2b0bdaa603da7a002b0","name":"Popup Builder <= 4.2.5 - Authenticated (Admin+) Server-Side Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-425-authenticated-admin-server-side-request-forgery","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.2.5. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal services.","date":"2024-01-17"},{"id":"eaeb5706-b19c-4266-b7df-889558ee2614","name":"popup-builder &lt; 4.2.6 - Admin+ SSRF &amp; File Read","link":"https:\/\/wpscan.com\/vulnerability\/eaeb5706-b19c-4266-b7df-889558ee2614","description":"The plugin does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."},{"cwe":"CWE-918","name":"Server-Side Request Forgery (SSRF)","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7ff51e296a4d87facca61c95f8fa001e70f41b92d9a0941db234fb693682b0ca","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-30184","name":"CVE-2024-30184","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-30184","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Looking Forward Software Incorporated. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n\/a through 4.2.6.","date":"2024-03-27"},{"id":"51c441cb40a29f73df647cda632daae3258a4171","name":"WordPress  Popup Builder Plugin    <= 4.2.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-2-6-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Popup Builder plugin to the latest available version (at least 4.2.7).\nLVT-tholv2k discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Popup Builder Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.2.7.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"bdc3b75f04f2a24c000c55d2f42b3bf777ee1318","name":"Popup Builder <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-426-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sg_popup shortcode in all versions up to, and including, 4.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-25"},{"id":"2e0821b9-7284-460b-b60d-eebf9439e9db","name":"Popup Builder &lt; 4.2.7 - Contributor Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/2e0821b9-7284-460b-b60d-eebf9439e9db","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s sg_popup shortcode due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"3.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"3.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c0099cb898deca8f697e942b749b9fcdb0b69b67683a95b7d4ef4370896682e9","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2506","name":"CVE-2024-2506","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2506","description":"[en] The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality in all versions up to, and including, 4.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-01"},{"id":"171021a81523f0e17369d8f51647ff793dcb54ba","name":"Popup Builder <= 4.2.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-427-authenticatedcontributor-stored-cross-site-scripting-via-custom-js","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality in all versions up to, and including, 4.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-31"},{"id":"865dc724723ff9e2d1a44db334bd19852dbb5c3c","name":"WordPress Popup Builder Plugin <= 4.2.7 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-2-7-authenticated-contributor-stored-cross-site-scripting-via-custom-js-vulnerability","description":"<p>WordPress Popup Builder Plugin <= 4.2.7 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Popup Builder<\/p><p>Link: https:\/\/wordpress.org\/plugins\/popup-builder\/#developers<\/p><p>Affected Version <= 4.2.7<\/p><p>Fixed in version 4.3.0 <\/p>","date":"2024-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"95248668214ea2738a81d2c11384f0d7b008f7286393fbf41e64c138174cf2e8","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2544","name":"CVE-2024-2544","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2544","description":"[en] The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscribers, and importing subscribers to conduct stored cross-site scripting attacks.","date":"2024-06-15"},{"id":"539c865f165246bd208258e6caa3371a81992cc1","name":"Popup Builder <= 4.3.0 - Missing Authorization in Multiple AJAX Actions","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-430-missing-authorization-in-multiple-ajax-actions","description":"The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscribers, and importing subscribers to conduct stored cross-site scripting attacks.","date":"2024-06-14"},{"id":"0ea86d4bd8cf6677a8af65611f265489881035f2","name":"WordPress Popup Builder Plugin <= 4.3.0 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-3-0-missing-authorization-in-multiple-ajax-actions-vulnerability","description":"<p>WordPress Popup Builder Plugin <= 4.3.0 is vulnerable to Broken Access Control<\/p><p>Software: Popup Builder<\/p><p>Link: https:\/\/wordpress.org\/plugins\/popup-builder\/#developers<\/p><p>Affected Version <= 4.3.0<\/p><p>Fixed in version 4.3.2 <\/p>","date":"2024-06-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d5229f743f7a2c21d97a2f73b8e4593a50f4d3ccdb2d006b8505efed10a9da87","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6696","name":"CVE-2023-6696","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6696","description":"[en] The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions contain a nonce check, the nonce can be obtained from the profile page of a logged-in user. This allows subscribers to perform several actions including deleting subscribers and perform blind Server-Side Request Forgery.","date":"2024-06-15"},{"id":"52693bfeb8dd4fc66b3132d39f9cf8f592477f11","name":"Popup Builder \u2013 Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-create-highly-converting-mobile-friendly-marketing-popups-431-missing-authorization-and-nonce-exposure","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions contain a nonce check, the nonce can be obtained from the profile page of a logged-in user. This allows subscribers to perform several actions including deleting subscribers and perform blind Server-Side Request Forgery.","date":"2024-06-14"},{"id":"27da4f4046486d110b79dbec6f58825a43571db6","name":"WordPress Popup Builder Plugin <= 4.3.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-3-1-missing-authorization-and-nonce-exposure-vulnerability","description":"<p>WordPress Popup Builder Plugin <= 4.3.1 is vulnerable to Broken Access Control<\/p><p>Software: Popup Builder<\/p><p>Link: https:\/\/wordpress.org\/plugins\/popup-builder\/#developers<\/p><p>Affected Version <= 4.3.1<\/p><p>Fixed in version 4.3.2 <\/p>","date":"2024-06-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"8.1","severity":"h","exploitable":"2.8","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"8.1","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"2.8","impact":"5.2"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9dc3a6e09b28db54fbf8fc9069a7ad4445f861520013cff9baf15c05606e696a","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2541","name":"CVE-2024-2541","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2541","description":"[en] The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an administrator has imported subscribers via a CSV file. This data may include the first name, last name, e-mail address, and potentially other personally identifiable information of subscribers.","date":"2024-08-29"},{"id":"03581549a4488d21015920741d7424ae11ade38f","name":"Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-433-sensitive-information-exposure-via-imported-subscribers-csv-file","description":"The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an administrator has imported subscribers via a CSV file. This data may include the first name, last name, e-mail address, and potentially other personally identifiable information of subscribers.","date":"2024-08-28"},{"id":"bafd4e7a10ab224a7b8d3df32e236e4b43c8ca3f","name":"WordPress Popup Builder Plugin <= 4.3.3 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-3-3-sensitive-information-exposure-via-imported-subscribers-csv-file-vulnerability","description":"<p>WordPress Popup Builder Plugin <= 4.3.3 is vulnerable to Sensitive Data Exposure<\/p><p>Software: Popup Builder<\/p><p>Link: https:\/\/wordpress.org\/plugins\/popup-builder\/#developers<\/p><p>Affected Version <= 4.3.3<\/p>","date":"2024-08-29"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6aa36984920f4dcc5c33b713ed3214ede18b4d242655a191becce23ddf02a61a","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-9428","name":"CVE-2024-9428","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-9428","description":"[en] The Popup Builder  WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2024-12-12"},{"id":"f83cf4224ab53a0649ba09273f5cf3d5a85ca449","name":"Popup Builder <= 4.3.4 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-434-authenticated-admin-stored-cross-site-scripting","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-11-21"},{"id":"68f55a0022302168621b33732411f99c3f9bcd4a","name":"WordPress Popup Builder Plugin < 4.3.5 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-builder\/vulnerability\/wordpress-popup-builder-plugin-4-3-5-admin-stored-xss-vulnerability","description":"<p>WordPress Popup Builder Plugin < 4.3.5 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Popup Builder<\/p><p>Fixed in version 4.3.5 <\/p><p>Affected Version < 4.3.5<\/p><p>CVE: CVE-2024-9428<\/p>","date":"2024-12-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c8691ee7d06299ee45e8b24b7df2eeeac1a7839344760a7040e4d7d90c7671f7","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.4.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13079","name":"CVE-2025-13079","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13079","description":"[en] The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for unauthenticated attackers to unsubscribe arbitrary subscribers from mailing lists via brute-forcing the unsubscribe token, granted they know the victim's email address","date":"2026-02-19"},{"id":"115b5390e4d343d0e69fa669ec98e03d1380a74b","name":"Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-create-highly-converting-mobile-friendly-marketing-popups-442-improper-authorization-to-unauthenticated-subscriber-removal-via-predictable-tokens","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for unauthenticated attackers to unsubscribe arbitrary subscribers from mailing lists via brute-forcing the unsubscribe token, granted they know the victim's email address","date":"2026-02-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-1241","name":"Use of Predictable Algorithm in Random Number Generator","description":"The device uses an algorithm that is predictable and generates a pseudo-random number."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"61b2d4b37ed452f5fbdf0f2d776656288b151244ab1087b36acbc5f2d3249c94","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9856","name":"Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9856","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"71720bfe3d47a5cca83823b2ac54831e857834b6","name":"Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-builder\/popup-builder-create-highly-converting-mobile-friendly-marketing-popups-441-authenticated-contributor-stored-cross-site-scripting","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-12"},{"id":"EUVD-2025-203244","name":"EUVD-2025-203244","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-203244","description":"The Popup Builder \u2013 Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-13"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"5d57f866375c7ef71da54835282b873d0f3aa02e391ae9412d83d83ca4fc2db4","name":"Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] <= 3.49 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.49","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2019-25744","name":"CVE-2019-25744","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-25744","description":"[en] WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title field that execute when pages or posts display popup selections.","date":"2026-06-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1780636282"}