Vulnerabilities
Vulnerable Software
Sygnoos:  >> Popup Builder  >> 4.0.7  Security Vulnerabilities
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link
CVSS Score
9.8
EPSS Score
0.623
Published
2022-03-28


Contact Us

Shodan ® - All rights reserved