QID 730988
Date Published: 2023-11-30
QID 730988: WordPress Plugin Popup Builder SQL Injection Vulnerability
Popup Builder is a Perfect solution for any WordPress website. With a wide range of WordPress popup types, conditions, and events (From Image Popup to Countdown popup, Exit Intent to GeoTargeting) Popup Builder helps you create high converting, promotional and informative popups, increase conversion rates and boost sales while reaching your marketing goals.
CVE-2020-9006 : The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable.
Affected Versions:
WordPress Popup Builder plugin versions from 2.2.8 to 2.6.7.6
QID Detection Logic:
This unauthenticated detection checks for installed vulnerable version for Popup Builder Plugin using Blind Elephant Fingerprint technique.
Successful exploitation of this vulnerability may allow high privileged attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- WP Popup-Builder Plugin Release Notes -
wordpress.org/plugins/popup-builder/#developers
CVEs related to QID 730988
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Popup Builder plugin |
|