Show filters
44 Total Results
Displaying 31-40 of 44
Sort by:
Attacker Value
Unknown
CVE-2022-29495
Disclosure Date: June 30, 2022 (last updated October 07, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.
0
Attacker Value
Unknown
CVE-2022-32289
Disclosure Date: June 17, 2022 (last updated October 07, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.
0
Attacker Value
Unknown
CVE-2022-28612
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.
0
Attacker Value
Unknown
CVE-2022-0479
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link
0
Attacker Value
Unknown
CVE-2022-0228
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection
0
Attacker Value
Unknown
CVE-2021-25082
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2022-0214
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
0
Attacker Value
Unknown
CVE-2021-24718
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
0
Attacker Value
Unknown
CVE-2021-24152
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
0