First published: Mon Feb 21 2022(Updated: )
The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sygnoos Popup Builder | <4.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0228 is a vulnerability found in the Popup Builder WordPress plugin before version 4.0.7.
CVE-2022-0228 has a severity rating of high with a CVSS score of 7.2.
The Popup Builder plugin before version 4.0.7 is affected by CVE-2022-0228.
CVE-2022-0228 allows high privilege users to perform SQL injection.
To fix CVE-2022-0228, you should update the Popup Builder plugin to version 4.0.7 or later.