Extension WordPress
Vulnérabilités Popup Builder – Create highly converting, mobile friendly marketing popups., page 2
Cette page rassemble les failles publiées pour Popup Builder – Create highly converting, mobile friendly marketing popups., leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Popup Builder – Create highly converting, mobile friendly marketing popups.
23 fiches
Popup Builder <= 3.63 – Unauthenticated Stored Cross-Site Scripting
An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com/classes/Ajax.php. It is possible for an unauthenticated attacker to insert malicious…
*-3.63
3.64.1
12/03/2020
Popup Builder 2.2.8 – 2.6.7.6 – PHP Object Injection
The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress…
2.2.8-2.6.7.6
3.0
16/02/2020
Popup Builder <= 3.44 – SQL Injection
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers…
*-3.44
3.45
06/08/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.