Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Popup Builder HIGH 7.5
CVE-2024-2541

The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscriber…

Fix: after 4.3.3
Fix from $1,950 2024-08-29
Popup Builder HIGH 8.1
CVE-2023-6696

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of function…

Fix: 4.3.2+
Fix from $1,950 2024-06-15
Popup Builder MEDIUM 6.4
CVE-2024-2544

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all A…

Fix: 4.3.2+
Fix from $1,600 2024-06-15
Social Media Share Buttons HIGH 8.8
CVE-2024-2721

Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media S…

Fix: after 2.1.0
Fix from $1,950 2024-03-20
Social Media Share Buttons HIGH 8.8
CVE-2024-1685

The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserializa…

Fix: after 2.1.0
Fix from $1,950 2024-03-16
Popup Builder HIGH 7.2
CVE-2023-6294

The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the adminis…

Fix: 4.2.6+
Fix from $1,950 2024-02-12
Popup Builder MEDIUM 6.1
CVE-2023-6000

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them,…

Fix: 4.2.3+
Fix from $1,600 2024-01-01
Popup Builder CRITICAL 9.8
CVE-2022-0479EPSS 44%

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statem…

Fix: 4.1.1+
Fix from $2,300 2022-03-28
Popup Builder HIGH 7.2
CVE-2022-0228EPSS 6%

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL sta…

Fix: 4.0.7+
Fix from $1,950 2022-02-21
Popup Builder HIGH 8.8
CVE-2021-25082EPSS 5%

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leadin…

Fix: 4.0.7+
Fix from $1,950 2022-02-21
Popup Builder MEDIUM 6.1
CVE-2021-24152

The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

Fix: 3.74+
Fix from $1,600 2021-04-05
Popup Builder MEDIUM 6.3
CVE-2020-10195

The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalatio…

Fix: 3.64.1+
Fix from $1,600 2020-03-13
Popup Builder MEDIUM 6.1
CVE-2020-10196

An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing pop…

Fix: 3.64.1+
Fix from $1,600 2020-03-13
Popup Builder CRITICAL 9.8
CVE-2020-9006EPSS 9%

The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via…

Fix: after 2.6.7.6
Fix from $2,300 2020-02-17
Popup Builder CRITICAL 9.8
CVE-2019-14695

A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability wou…

Fix: 3.45+
Fix from $2,300 2019-08-06