CVE Database /
CVE-2020-9006
CVE · Critical
CVE-2020-9006 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2020-9006
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.0.2 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Critical
9.8
|
< 3.0.2
|
3.0.2 |
2020-02-16 |
—
|
CVE-2020-9006
The Popup Builder plugin through version 2.6.7.6 contains a SQL injection vulnerability triggered by unsafe PHP deserialization of the attachmentUrl POST parameter, which attackers can exploit to create arbitrary WordPress administrator accounts and execute remote code. Versions 2.2.8 through 2.5.3 lack nonce verification for this vulnerable endpoint, while later versions 2.5.4 through 2.6.7.6 require a valid nonce for exploitation. The vulnerability has been resolved in the 3.x branch of the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings