S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0228 Scanner

CVE-2022-0228 scanner - SQL Injection vulnerability in WordPress Popup Builder Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0228
7.2
CVSS

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Popup Builder – Create highly converting, mobile friendly marketing popups.
AFFECTED< 4.0.7SAFE ✓≥ 4.0.7
Updated Aug 22, 2026View on NVD →
Detail

The Popup Builder plugin for WordPress is a powerful tool designed to help website owners create and manage interactive popups for their sites. Developed by Sygnoos, it is widely utilized for engaging visitors, collecting leads, and delivering targeted content or offers. This plugin is favored for its flexibility, ease of use, and integration capabilities with other WordPress tools and services. It is typically used by digital marketers, e-commerce site owners, and anyone looking to enhance user interaction on their WordPress site.

Specifically, the vulnerability is exploited through the admin dashboard where the 'orderby' and 'order' parameters are not properly sanitized before being incorporated into SQL queries. This oversight allows an attacker with administrative access to execute arbitrary SQL commands, which could result in data exfiltration, database corruption, or unauthorized administrative actions. The exploit is conducted via crafted requests to the 'admin-post.php' page, demonstrating a critical need for stringent input validation and parameter sanitization practices.

The exploitation of this SQL Injection vulnerability can lead to severe consequences including theft of sensitive information, unauthorized changes to website content, and the exposure of user data. Attackers could potentially gain control over the website, execute administrative actions without proper authorization, or access confidential database information. This poses significant risks to data privacy, website integrity, and user trust.

By leveraging the security scanning solutions provided by S4E, website owners can proactively identify and mitigate vulnerabilities like the SQL Injection flaw in the Popup Builder plugin. Our platform offers comprehensive vulnerability assessments, enabling users to safeguard their digital assets against sophisticated cyber threats. Membership benefits include access to detailed reports, real-time alerts, and tailored security recommendations, ensuring your website remains secure and compliant. Enhance your cybersecurity posture with S4E and protect your site from potential breaches.

 

References

Solution Advice
  1. Immediately update the Popup Builder plugin to version 4.0.7 or later.
  2. Regularly audit and update all WordPress plugins and themes to their latest versions.
  3. Implement web application firewalls (WAFs) to detect and block SQL Injection attempts.
  4. Limit the database privileges assigned to the WordPress application to only what is necessary for its operation.
  5. Educate users with administrative access on the importance of secure practices and the risks associated with SQL Injection.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.