Skip to main content

Vendor/product archive

sygnoos / popup_builder CVEs

Beta · best-effort

18 CVEs tagged to sygnoos / popup_builder3 Critical, 5 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2024-9428

Published Dec 12, 2024

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Si…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2541

Published Aug 29, 2024

The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2544

Published Jun 15, 2024

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it pos…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6696

Published Jun 15, 2024

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabil…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6294

Published Feb 12, 2024

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF at…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-6000

Published Jan 1, 2024

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XS…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2023-3226

Published Sep 25, 2023

The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Sit…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-29495

Published Jul 22, 2022

Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32289

Published Jul 21, 2022

Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1894

Published Jul 11, 2022

The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0479

Published Mar 28, 2022

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers adm…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-0228

Published Feb 21, 2022

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25082

Published Feb 21, 2022

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-24152

Published Apr 5, 2021

The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10196

Published Mar 13, 2020

An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax acti…

CVSS 6.1 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2020-10195

Published Mar 13, 2020

The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to co…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2020-9006

Published Feb 17, 2020

The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14695

Published Aug 6, 2019

A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1