QID 730988

Date Published: 2023-11-30

QID 730988: WordPress Plugin Popup Builder SQL Injection Vulnerability

Popup Builder is a Perfect solution for any WordPress website. With a wide range of WordPress popup types, conditions, and events (From Image Popup to Countdown popup, Exit Intent to GeoTargeting) Popup Builder helps you create high converting, promotional and informative popups, increase conversion rates and boost sales while reaching your marketing goals.

CVE-2020-9006 : The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable.

Affected Versions:
WordPress Popup Builder plugin versions from 2.2.8 to 2.6.7.6

QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Popup Builder Plugin using Blind Elephant Fingerprint technique.

Successful exploitation of this vulnerability may allow high privileged attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to WP ERP version 2.6.7.6 and later to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730988

    Software Advisories
    Advisory ID Software Component Link
    Popup Builder plugin URL Logo wordpress.org/plugins/popup-builder/#developers