sygnoos Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with sygnoos products.
Products
- Popup Builder (WordPress plugin)2 vulnerabilities
- popup_builder2 vulnerabilities
- social_media_share_buttons2 vulnerabilities
- Social Media Share Buttons1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-2721HIGH | WordPress Social Media Share Buttons plugin <= 2.1.0 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0. CWE-502Mar 20, 2024 | CVSS8.2v3.1 | EPSS0.672% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1685HIGH | Social Media Share Buttons <= 2.1.0 - Authenticated (Subscriber+) PHP Object InjectionThe Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacke… CWE-502Mar 16, 2024 | CVSS8.8v3.1 | EPSS0.775% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6000MEDIUM | Popup Builder < 4.2.3 - Unauthenticated Stored XSSThe Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks. | CVSS6.1v3.1 | EPSS2% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-29495MEDIUM | WordPress Popup Builder plugin <= 4.1.11 - Cross-Site Request Forgery (CSRF) leading to plugin settings updateCross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings. | CVSS5.4v3.1 | EPSS0.495% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-32289MEDIUM | WordPress Popup Builder plugin <= 4.1.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Popup Status ChangeCross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change. CWE-352Jul 21, 2022 | CVSS5.4v3.1 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25082HIGH | Popup Builder < 4.0.7 - LFI to RCEThe Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR | CVSS8.8v3.1 | EPSS5.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |