CVE-2021-25082
21.02.2022, 11:15
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR
Vendor | Product | Version |
---|---|---|
sygnoos | popup_builder | 𝑥 < 4.0.7 |
𝑥
= Vulnerable software versions