CVE Database /
CVE-2019-14695
CVE · Critical
CVE-2019-14695 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-14695
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.8
|
< 3.45
|
3.45 |
2019-08-06 |
—
|
CVE-2019-14695
The Popup Builder plugin for WordPress before version 3.45 contains a SQL injection vulnerability in the com/libs/Table.php file where subscriber table ordering parameters are not properly sanitized. An attacker could exploit this flaw to execute arbitrary SQL commands on the affected WordPress installation without requiring authentication. The vulnerability impacts all versions prior to 3.45 where this input validation weakness exists.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings