CVE-2021-25082: Popup Builder < 4.0.7 - LFI to RCE
Published Feb 21, 2022
·Updated
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpbtype parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR
Affected Software
1 affected component
Sygnoos Popup Builder Wordpress<4.0.7
Event History
Feb 21, 2022
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Popup Builder WordPress plugin issue?
The vulnerability ID for the Popup Builder WordPress plugin issue is CVE-2021-25082.
2
What is the severity rating for CVE-2021-25082?
CVE-2021-25082 has a severity rating of 8.8 (High).
3
What is the affected software version for CVE-2021-25082?
The affected software version for CVE-2021-25082 is Popup Builder plugin before 4.0.7.
4
What is the CVE CWE ID for Popup Builder vulnerability?
The CVE CWE ID for Popup Builder vulnerability is CWE-22.
5
How can I fix the Popup Builder vulnerability?
To fix the Popup Builder vulnerability, update the plugin to version 4.0.7 or later.