Products

Showing 6 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
sygnoos vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Social Media Share Buttons plugin <= 2.1.0 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.

CWE-502Mar 20, 2024
CVSS8.2v3.1EPSS0.672%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Social Media Share Buttons <= 2.1.0 - Authenticated (Subscriber+) PHP Object Injection

The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacke

CWE-502Mar 16, 2024
CVSS8.8v3.1EPSS0.775%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Popup Builder < 4.2.3 - Unauthenticated Stored XSS

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

CWE-79Jan 1, 20241 related artifact
CVSS6.1v3.1EPSS2%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress Popup Builder plugin <= 4.1.11 - Cross-Site Request Forgery (CSRF) leading to plugin settings update

Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.

CWE-352Jul 22, 20221 related artifact
CVSS5.4v3.1EPSS0.495%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress Popup Builder plugin <= 4.1.0 - Cross-Site Request Forgery (CSRF) vulnerability leading to Popup Status Change

Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.

CWE-352Jul 21, 2022
CVSS5.4v3.1EPSS0.318%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Popup Builder < 4.0.7 - LFI to RCE

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

CWE-22Feb 21, 20221 related artifact
CVSS8.8v3.1EPSS5.23%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX