Record summary

CVE-2022-0228 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Popup Builder – Create highly converting, mobile friendly marketing popups.

CVE List4.0.7 to < 4.0.7affected

Nuclei templates

1
ProjectDiscoveryHIGHPopup Builder < 4.0.7 - SQL InjectionCVSS 7.2

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection.

Impact

Authenticated administrators with high privileges can exploit SQL injection to extract database contents, potentially exposing sensitive WordPress data and user credentials.

Remediation

update to v.4.0.7

WeaknessesCWE-89
Authorsr3Y3r53
Template tagstime-based-sqlicve2022cvewordpresswp-pluginwpwpscanpopup-buildersygnoossqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/popup-builder/
FOFA: body=/wp-content/plugins/popup-builder/

Source: ProjectDiscovery

References

3