Record summary

CVE-2022-0479 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Popup Builder – Create highly converting, mobile friendly marketing popups.

CVE List4.1.1 to < 4.1.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALPopup Builder Plugin - SQL Injection and Cross-Site ScriptingCVSS 9.8

The Popup Builder WordPress plugin before 4.1.1 is vulnerable to SQL Injection and Reflected XSS via the sgpb-subscription-popup-id parameter.

Impact

Allows attackers to execute malicious SQL queries and inject scripts into web pages

Remediation

Update Popup Builder Plugin to the latest secure version

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2022wpwp-pluginwordpresspopup-builderxsssqliauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/popup-builder"

Source: ProjectDiscovery

References

3