plugin

Popup Builder Vulnerabilities

50 known security issues reported for the Popup Builder WordPress plugin. Most recent disclosed Feb 19, 2026.

3 critical 6 high 14 medium

Running Popup Builder on your site? Check whether your installed version is affected.

Scan your site free

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.4.3

unknown

[en] The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for unauthenti...

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Feb 19, 2026

CVE-2025-13079 on NVD →

Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens

medium

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for unauthenticated...

CVSS:
5.3
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Feb 18, 2026

CVE-2025-13079 on NVD →

Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This...

CVSS:
6.4
Affected:
up to 4.4.1
Fixed in:
4.4.2
Disclosed:
Dec 12, 2025

CVE-2025-9856 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.5

unknown

[en] The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 4.3.5
Fixed in:
4.3.5
Disclosed:
Dec 12, 2024

CVE-2024-9428 on NVD →

Popup Builder <= 4.3.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

CVSS:
4.4
Affected:
up to 4.3.4
Fixed in:
4.3.5
Disclosed:
Nov 21, 2024

CVE-2024-9428 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.7

unknown

[en] The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.3 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an administrator has imported subscribers via a CSV file. This...

Affected:
up to 4.3.7
Fixed in:
4.3.7
Disclosed:
Aug 29, 2024

CVE-2024-2541 on NVD →

Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File

medium

The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an administrator has imported subscribers via a CSV file. This data...

CVSS:
5.3
Affected:
up to 4.3.6
Fixed in:
4.3.7
Disclosed:
Aug 28, 2024

CVE-2024-2541 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2

unknown

[en] The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting su...

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Jun 15, 2024

CVE-2024-2544 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2

unknown

[en] The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions contain a nonce check, the nonce can be...

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Jun 15, 2024

CVE-2023-6696 on NVD →

Popup Builder – Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure

high

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions contain a nonce check, the nonce can be obta...

CVSS:
8.1
Affected:
up to 4.3.1
Fixed in:
4.3.2
Disclosed:
Jun 14, 2024

CVE-2023-6696 on NVD →

Popup Builder <= 4.3.0 - Missing Authorization in Multiple AJAX Actions

high

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscri...

CVSS:
7.4
Affected:
up to 4.3.0
Fixed in:
4.3.2
Disclosed:
Jun 14, 2024

CVE-2024-2544 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.0

unknown

[en] The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality in all versions up to, and including, 4.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Jun 1, 2024

CVE-2024-2506 on NVD →

Popup Builder <= 4.2.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS

medium

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality in all versions up to, and including, 4.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

CVSS:
6.4
Affected:
up to 4.2.7
Fixed in:
4.3.0
Disclosed:
May 31, 2024

CVE-2024-2506 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.7

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Looking Forward Software Incorporated. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 4.2.6.

Affected:
up to 4.2.7
Fixed in:
4.2.7
Disclosed:
Mar 27, 2024

CVE-2024-30184 on NVD →

Popup Builder <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sg_popup shortcode in all versions up to, and including, 4.2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This m...

CVSS:
6.4
Affected:
up to 4.2.6
Fixed in:
4.2.7
Disclosed:
Mar 25, 2024

CVE-2024-30184 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.6

unknown

[en] The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.

Affected:
up to 4.2.6
Fixed in:
4.2.6
Disclosed:
Feb 12, 2024

CVE-2023-6294 on NVD →

Popup Builder <= 4.2.5 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.2.5. This makes it possible for authenticated attackers, with administrator-level access and above, to make web requests to arbitrary...

CVSS:
5.5
Affected:
up to 4.2.5
Fixed in:
4.2.6
Disclosed:
Jan 17, 2024

CVE-2023-6294 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.3

unknown

[en] The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS attacks.

Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Jan 1, 2024

CVE-2023-6000 on NVD →

Popup Builder <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting

medium

The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popups in versions up to 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an i...

CVSS:
6.1
Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Dec 11, 2023

CVE-2023-6000 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.2

unknown

[en] The Popup Builder WordPress plugin before 4.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 4.2.2
Fixed in:
4.2.2
Disclosed:
Sep 25, 2023

CVE-2023-3226 on NVD →

Popup Builder <= 4.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitra...

CVSS:
4.4
Affected:
up to 4.2.1
Fixed in:
4.2.2
Disclosed:
Aug 28, 2023

CVE-2023-3226 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.12

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.11 at WordPress allows an attacker to update plugin settings.

Affected:
up to 4.1.12
Fixed in:
4.1.12
Disclosed:
Jul 22, 2022

CVE-2022-29495 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.11

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup status change.

Affected:
up to 4.1.11
Fixed in:
4.1.11
Disclosed:
Jul 21, 2022

CVE-2022-32289 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.11

unknown

[en] The Popup Builder WordPress plugin before 4.1.11 does not escape and sanitize some settings, which could allow high privilege users to perform Stored Cross-Site Scripting attacks when the unfiltred_html is disallowed

Affected:
up to 4.1.11
Fixed in:
4.1.11
Disclosed:
Jul 11, 2022

CVE-2022-1894 on NVD →

Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.1.11 - Cross-Site Request Forgery to Settings Update

high

The "Popup Builder – Create highly converting, mobile friendly marketing popups." plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.11. This is due to missing or incorrect nonce validation on the saveSettings() function. This makes it possible for unauthenticated at...

CVSS:
8.8
Affected:
up to 4.1.11
Fixed in:
4.1.12
Disclosed:
Jun 30, 2022

CVE-2022-29495 on NVD →

Popup Builder <= 4.1.10 - Authenticated (Admin+) Cross-Site Scripting

medium

The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions to inject arbitrary web scripts in pages that...

CVSS:
5.5
Affected:
up to 4.1.10
Fixed in:
4.1.11
Disclosed:
Jun 20, 2022

CVE-2022-1894 on NVD →

Popup Builder <= 4.1.0 - Cross-Site Request Forgery

medium

The Popup Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing nonce validation on thechangePopupStatus() function. This makes it possible for unauthenticated attackers to change a popup's status via a forged request granted they can tr...

CVSS:
4.3
Affected:
up to 4.1.0
Fixed in:
4.1.11
Disclosed:
Jun 17, 2022

CVE-2022-32289 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1

unknown

[en] The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in...

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Mar 28, 2022

CVE-2022-0479 on NVD →

Popup Builder <= 4.1.0 - SQL Injection

critical

The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site Scripting attack against a logged in admin...

CVSS:
9.8
Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Mar 7, 2022

CVE-2022-0479 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1

unknown

[en] The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 21, 2022

CVE-2022-0228 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1

unknown

[en] The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

Affected:
up to 4.1.1
Fixed in:
4.1.1
Disclosed:
Feb 21, 2022

CVE-2021-25082 on NVD →

Popup Builder <= 4.0.6 - Local File Inclusion and PHAR Deserialization

high

The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR

CVSS:
8.8
Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Jan 24, 2022

CVE-2021-25082 on NVD →

Popup Builder <= 4.0.6 - Authenticated SQL Injection via order & orderby Parameters

high

The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, which could allow high privilege users to perform SQL injection

CVSS:
7.2
Affected:
up to 4.0.7
Fixed in:
4.0.7
Disclosed:
Jan 24, 2022

CVE-2022-0228 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.74

unknown

[en] The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

Affected:
up to 3.74
Fixed in:
3.74
Disclosed:
Apr 5, 2021

CVE-2021-24152 on NVD →

Popup Builder <= 3.73 - Reflected Cross-Site Scripting

medium

The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

CVSS:
6.1
Affected:
up to 3.73
Fixed in:
3.74
Disclosed:
Feb 2, 2021

CVE-2021-24152 on NVD →

Popup Builder <= 3.72 Missing Authorization on AJAX actions

medium

The Popup Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.71 due to missing capability checks on various actions called via AJAX. This makes it possible for attackers to import subscribers and send newsletters among other actions.

CVSS:
6.3
Affected:
up to 3.71
Fixed in:
3.72
Disclosed:
Jan 28, 2021

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72

unknown

Authenticated Deleting/Importing Subscribers vulnerability found by Dave Jong (WebARX Security) in WordPress Popup Builder plugin (versions <= 3.71).

Affected:
up to 3.72
Fixed in:
3.72
Disclosed:
Jan 28, 2021

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72

unknown

Authenticated Newsletter Send With Custom Content And Sender vulnerability found by Dave Jong (WebARX Security) in WordPress Popup Builder plugin (versions <= 3.71).

Affected:
up to 3.72
Fixed in:
3.72
Disclosed:
Jan 28, 2021

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72

unknown

Authenticated Local File Inclusion (LFI) vulnerability found by Dave Jong (WebARX Security) in WordPress Popup Builder plugin (versions <= 3.71).

Affected:
up to 3.72
Fixed in:
3.72
Disclosed:
Jan 28, 2021

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72

unknown

The Popup Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 3.71 due to missing capability checks on various actions called via AJAX. This makes it possible for attackers to import subscribers and send newsletters among other actions.

Affected:
up to 3.72
Fixed in:
3.72
Disclosed:
Jan 28, 2021

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.69.7

unknown

Multiple Stored Cross-Site Scripting (XSS) vulnerabilities were found by Ilca Lucian Florin in the WordPress Popup Builder plugin (versions <= 3.69.6).

Affected:
up to 3.69.7
Fixed in:
3.69.7
Disclosed:
Dec 14, 2020

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1

unknown

[en] An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com/classes/Ajax.php. It is possible for an unauthenticated attacker to insert malicious JavaScript in several of the popup's fiel...

Affected:
up to 3.64.1
Fixed in:
3.64.1
Disclosed:
Mar 13, 2020

CVE-2020-10196 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1

unknown

[en] The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post.php, an authenticated attacker with minimal (subscriber-level) p...

Affected:
up to 3.64.1
Fixed in:
3.64.1
Disclosed:
Mar 13, 2020

CVE-2020-10195 on NVD →

Popup Builder <= 3.63 - Unauthenticated Stored Cross-Site Scripting

high

An XSS vulnerability in the popup-builder plugin before 3.64.1 for WordPress allows remote attackers to inject arbitrary JavaScript into existing popups via an unsecured ajax action in com/classes/Ajax.php. It is possible for an unauthenticated attacker to insert malicious JavaScript in several of the popup's fields by...

CVSS:
8.3
Affected:
up to 3.63
Fixed in:
3.64.1
Disclosed:
Mar 12, 2020

CVE-2020-10196 on NVD →

Popup Builder <= 3.63 - Authenticated Settings Modification, Configuration Disclosure, and User Data Export

medium

The Popup Builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post.php, an authenticated attacker with minimal (subscriber-level) permis...

CVSS:
6.3
Affected:
up to 3.63
Fixed in:
3.64.1
Disclosed:
Mar 12, 2020

CVE-2020-10195 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.0.2

unknown

[en] The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading t...

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Feb 17, 2020

CVE-2020-9006 on NVD →

Popup Builder 2.2.8 - 2.6.7.6 - PHP Object Injection

critical

The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary WordPress Administrator account, leading to pos...

CVSS:
9.8
Affected:
2.2.8 – 2.6.7.6
Fixed in:
3.0
Disclosed:
Feb 16, 2020

CVE-2020-9006 on NVD →

Popup Builder <= 3.44 - SQL Injection

critical

A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.

CVSS:
9.8
Affected:
up to 3.44
Fixed in:
3.45
Disclosed:
Aug 6, 2019

CVE-2019-14695 on NVD →

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45

unknown

SQL Injection (SQLi) vulnerability found by Tin Duong (Fortinet FortiGuard Labs) in WordPress Popup Builder plugin (versions <= 3.44).

Affected:
up to 3.45
Fixed in:
3.45
Disclosed:
Aug 6, 2019

Popup Builder &#8211; Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45

unknown

[en] A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.

Affected:
up to 3.45
Fixed in:
3.45
Disclosed:
Aug 6, 2019

CVE-2019-14695 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database