sygnoos Vulnerabilities and Affected Products
Vulnerabilities associated with popup_builder.
Products
Clear product- Popup Builder (WordPress plugin)2 vulnerabilities
- popup_builder2 vulnerabilities
- social_media_share_buttons2 vulnerabilities
- Social Media Share Buttons1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-6000MEDIUM | Popup Builder < 4.2.3 - Unauthenticated Stored XSSThe Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks. | CVSS6.1v3.1 | EPSS2% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-25082HIGH | Popup Builder < 4.0.7 - LFI to RCEThe Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR | CVSS8.8v3.1 | EPSS5.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |