CVE Database /
CVE-2020-10196
CVE · Medium
CVE-2020-10196 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-10196, CVE-2020-10195
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 3.64.1
|
3.64.1 |
2020-03-12 |
—
|
CVE-2020-10196, CVE-2020-10195
The Popup Builder plugin before version 3.64.1 contains a cross-site scripting vulnerability in its AJAX handling code that allows unauthenticated attackers to inject malicious JavaScript into popups. An attacker can exploit an unsecured AJAX action by sending a request to wp-admin/admin-ajax.php with the sgpb_autosave parameter, including the popup ID and arbitrary JavaScript payload in the allPopupData field. The injected script will execute in visitors' browsers when they view the affected page, as the plugin automatically wraps the input in script tags, potentially bypassing web application firewalls.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings