CVE-2022-0228: Popup Builder < 4.0.7 - Admin+ SQL Injection
Published Feb 21, 2022
·Updated
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection
Affected Software
1 affected component
Sygnoos Popup Builder Wordpress<4.0.7
Event History
Feb 21, 2022
CVE Published
via MITRE·10:46 AM
Data Sourced
via MITRE·10:46 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-0228?
CVE-2022-0228 is a vulnerability found in the Popup Builder WordPress plugin before version 4.0.7.
2
What is the severity of CVE-2022-0228?
CVE-2022-0228 has a severity rating of high with a CVSS score of 7.2.
3
How can the Popup Builder plugin be affected by CVE-2022-0228?
The Popup Builder plugin before version 4.0.7 is affected by CVE-2022-0228.
4
What is the impact of CVE-2022-0228?
CVE-2022-0228 allows high privilege users to perform SQL injection.
5
How can I fix CVE-2022-0228?
To fix CVE-2022-0228, you should update the Popup Builder plugin to version 4.0.7 or later.