CVE · Critical

CVE-2019-14695 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-14695 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.45 3.45 2019-08-06

CVE-2019-14695

The Popup Builder plugin for WordPress before version 3.45 contains a SQL injection vulnerability in the com/libs/Table.php file where subscriber table ordering parameters are not properly sanitized. An attacker could exploit this flaw to execute arbitrary SQL commands on the affected WordPress installation without requiring authentication. The vulnerability impacts all versions prior to 3.45 where this input validation weakness exists.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.