S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 18, 2025

CVE-2021-25082 Scanner

CVE-2021-25082 Scanner - Remote Code Execution vulnerability in WordPress Popup Builder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25082
8.8
CVSS

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Popup Builder – Create highly converting, mobile friendly marketing popups.
AFFECTED< 4.0.7SAFE ✓≥ 4.0.7
Updated Aug 21, 2026View on NVD →
Detail

The WordPress Popup Builder plugin is widely used by website administrators to create and manage pop-up elements on WordPress sites. It allows for the effortless incorporation of custom pop-up designs to capture leads, integrate marketing campaigns, or display important messages to site visitors. This software is particularly favored by small-to-medium business owners and digital marketers aiming to enhance user engagement. Given its ease of use and extensive customization options, it is a popular choice among non-technical users as well. Alongside this, website developers might deploy this tool for its API capabilities allowing further custom integrations. The vulnerability discussed herein pertains specifically to versions before 4.0.7 of this plugin.

Remote Code Execution (RCE) vulnerabilities permit attackers to execute arbitrary code on a target system. In this case, the Flaw within the WordPress Popup Builder plugin version 4.0.7 or earlier can be exploited by unauthorized users. This flaw arises due to insufficient sanitization of the 'sgpb_type' parameter, making systems vulnerable to PHAR deserialization attacks. Such issues can potentially lead to complete compromise of the host server and exposure to additional layered attacks. It is crucial for affected installations to address this vulnerability to prevent unauthorized system access.

This vulnerability is introduced through inadequate input validation, specifically with the 'sgpb_type' parameter. The plugin's processing allows the inclusion of unwanted files through wrapper transformations, particularly PHAR, enabling arbitrary file execution. Attackers can manipulate this endpoint to include crafted files, deploying them successfully due to inadequate validation checks. This exploitation path can particularly be leveraged upon gaining preliminary system access through techniques like upload of 'malicious.zip' which contain PHP executable code disguised as a harmless file. Upon execution, it enables further attacks on the system, underpinning the critical severity linked with RCE exploits.

Exploitation of this vulnerability can facilitate the execution of arbitrary code on the target system. Once achieved, malicious users can install further malware, steal sensitive information, or manipulate data stored on the server. This includes gaining full administrative access over the plugin's associated website. Potentially, this could lead to severe business disruption, data breaches, or web defacement. Given the access potential offered by RCE, the ability to execute a wide array of harmful actions could jeopardize website integrity and user trust. Prompt remediation is essential to mitigate these possible adverse impacts.

REFERENCES

Solution Advice
  • Update the WordPress Popup Builder plugin to version 4.0.7 or later immediately to prevent exploitability.
  • Regularly audit installed WordPress plugins and themes for vulnerabilities and apply patches promptly.
  • Implement web application firewalls (WAFs) to help mitigate attempts to exploit known vulnerabilities.
  • Restrict access to administration panels to trusted IP addresses to reduce risk exposure.
  • Conduct regular system threat assessments to promptly identify and address any potential security gaps.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-25082 Scanner - Remote Code Execution vulnerability in WordPress Popup Builder | S4E