Show filters
44 Total Results
Displaying 31-40 of 44
Sort by:
Attacker Value
Unknown

CVE-2022-29495

Disclosure Date: June 30, 2022 (last updated October 07, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
Attacker Value
Unknown

CVE-2022-32289

Disclosure Date: June 17, 2022 (last updated October 07, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.
Attacker Value
Unknown

CVE-2022-28612

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.
Attacker Value
Unknown

CVE-2022-0479

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link
Attacker Value
Unknown

CVE-2022-0228

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection
Attacker Value
Unknown

CVE-2021-25082

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2022-0214

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
Attacker Value
Unknown

CVE-2021-24718

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2021-24152

Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.