CVE Database /
CVE-2022-0228
CVE · High
CVE-2022-0228 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0228
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.2
|
< 4.1.1
|
4.1.1 |
2022-01-24 |
—
|
CVE-2022-0228
The Popup Builder plugin before version 4.0.7 contains a SQL injection vulnerability in the admin dashboard where the orderby and order parameters are not adequately validated or escaped prior to being incorporated into SQL queries, potentially enabling administrators and other high-privilege users to execute arbitrary SQL commands.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings