Showing 2 vulnerabilities on this page for popup_builder

Signals CISA KEV Ransomware Nuclei
sygnoos vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Popup Builder < 4.2.3 - Unauthenticated Stored XSS

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

CWE-79Jan 1, 20241 related artifact
CVSS6.1v3.1EPSS2%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Popup Builder < 4.0.7 - LFI to RCE

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

CWE-22Feb 21, 20221 related artifact
CVSS8.8v3.1EPSS5.23%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX