Extension WordPress
Vulnérabilités Popup Builder – Create highly converting, mobile friendly marketing popups.
Cette page rassemble les failles publiées pour Popup Builder – Create highly converting, mobile friendly marketing popups., leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Popup Builder – Create highly converting, mobile friendly marketing popups.
23 fiches
Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.2 – Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using…
*-4.4.2
4.4.3
18/02/2026
Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization…
*-4.4.1
4.4.2
12/12/2025
Popup Builder <= 4.3.4 – Authenticated (Admin+) Stored Cross-Site Scripting
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.4 due to insufficient input sanitization and output…
*-4.3.4
4.3.5
21/11/2024
Popup Builder <= 4.3.6 – Sensitive Information Exposure via Imported Subscribers CSV File
The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an…
*-4.3.6
4.3.7
29/08/2024
Popup Builder – Create highly converting, mobile friendly marketing popups <= 4.3.1 – Missing Authorization and Nonce Exposure
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1.…
*-4.3.1
4.3.2
14/06/2024
Popup Builder <= 4.3.0 – Missing Authorization in Multiple AJAX Actions
The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and…
*-4.3.0
4.3.2
14/06/2024
Popup Builder <= 4.2.7 – Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality in all versions up to, and including, 4.2.7 due to insufficient input sanitization…
*-4.2.7
4.3.0
31/05/2024
Popup Builder <= 4.2.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sg_popup shortcode in all versions up to, and including, 4.2.6 due to insufficient input sanitization…
*-4.2.6
4.2.7
25/03/2024
Popup Builder <= 4.2.5 – Authenticated (Admin+) Server-Side Request Forgery
The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.2.5. This makes it possible for authenticated attackers, with administrator-level access…
*-4.2.5
4.2.6
17/01/2024
Popup Builder <= 4.2.2 – Unauthenticated Stored Cross-Site Scripting
The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popups in versions up to 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
[*, 4.2.3)
4.2.3
11/12/2023
Popup Builder <= 4.2.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.2.1
4.2.2
28/08/2023
Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.1.11 – Cross-Site Request Forgery to Settings Update
The "Popup Builder – Create highly converting, mobile friendly marketing popups." plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.11. This is due to missing or incorrect nonce validation on the…
*-4.1.11
4.1.12
30/06/2022
Popup Builder <= 4.1.10 – Authenticated (Admin+) Cross-Site Scripting
The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions…
*-4.1.10
4.1.11
20/06/2022
Popup Builder <= 4.1.0 – Cross-Site Request Forgery
The Popup Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing nonce validation on thechangePopupStatus() function. This makes it possible for unauthenticated attackers to change…
*-4.1.0
4.1.11
17/06/2022
Popup Builder <= 4.1.0 – SQL Injection
The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used…
[*, 4.1.1)
4.1.1
07/03/2022
Popup Builder <= 4.0.6 – Local File Inclusion and PHAR Deserialization
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be…
[*, 4.0.7)
4.0.7
24/01/2022
Popup Builder <= 4.0.6 – Authenticated SQL Injection via order & orderby Parameters
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL…
[*, 4.0.7)
4.0.7
24/01/2022
Popup Builder <= 3.73 – Reflected Cross-Site Scripting
The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
*-3.73
3.74
02/02/2021
Popup Builder <= 3.72 Missing Authorization on AJAX actions
The Popup Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.71 due to missing capability checks on various actions called via AJAX. This makes it possible for attackers to import subscribers…
*-3.71
3.72
28/01/2021
Popup Builder <= 3.63 – Authenticated Settings Modification, Configuration Disclosure, and User Data Export
The Popup Builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post.php, an authenticated attacker with minimal (subscriber-level) permissions…
*-3.63
3.64.1
12/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.