critical·Product Based Web Vulnerabilities·Updated Nov 26, 2024

CVE-2022-0479 Scanner

CVE-2022-0479 Scanner - SQL Injection & XSS vulnerability in Popup Builder Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2
Times Used
by S4E users
2
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0479
9.8
CVSS

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin opening a malicious link

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Popup Builder – Create highly converting, mobile friendly marketing popups.
AFFECTED< 4.1.1SAFE ✓≥ 4.1.1
Updated Aug 22, 2026View on NVD →
Detail

The Popup Builder Plugin is a popular WordPress plugin used to create and manage popups for websites. It is widely used by website administrators to engage users through promotional offers, subscriptions, and other interactive content. The plugin integrates seamlessly with WordPress and offers flexibility for customizing popup designs and behavior. However, like other WordPress plugins, its security is critical to maintaining the safety and integrity of websites.

This scanner identifies a SQL Injection vulnerability in the Popup Builder Plugin, which allows attackers to execute unauthorized SQL queries. By exploiting this vulnerability, attackers can manipulate database queries to disclose sensitive information or corrupt data. This type of attack targets the sgpb-subscription-popup-id parameter, exposing WordPress sites to significant security risks. The scanner also detects a Reflected Cross-Site Scripting (XSS) vulnerability associated with the same parameter.

The SQL Injection vulnerability stems from improper sanitization of user inputs in the sgpb-subscription-popup-id parameter. Malicious actors can insert custom SQL queries via this parameter, potentially leading to unauthorized access or data modification. Additionally, the reflected XSS flaw allows injecting malicious scripts into web pages, enabling further exploitation. The scanner inspects requests and server responses to verify the vulnerability's presence.

Exploiting this vulnerability can result in unauthorized database access, exposure of confidential information, or corruption of website data. It could also facilitate phishing attacks, redirecting users to malicious websites, or taking control of the WordPress site. The reflected XSS vulnerability can enable attackers to perform actions on behalf of unsuspecting users or steal sensitive data.

REFERENCES

Solution Advice
  • Update the Popup Builder Plugin to version 4.1.1 or higher.
  • Implement input validation to sanitize user inputs effectively.
  • Conduct regular plugin updates and vulnerability assessments.
  • Restrict database permissions to minimize potential exploitation impacts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.