PT-2020-20425 · WordPress · Popup Builder
Yeraisci
·
Published
2020-02-17
·
Updated
2021-07-21
·
CVE-2020-9006
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Popup Builder plugin versions 2.2.8 through 2.6.7.6
Description
The issue allows for SQL injection via PHP Deserialization on attacker-controlled data with the
attachmentUrl POST variable in the sgImportPopups function in sg popup ajax.php. This enables the creation of an arbitrary WordPress Administrator account, potentially leading to Remote Code Execution since Administrators can run PHP code on WordPress instances.Recommendations
For versions 2.2.8 through 2.6.7.6, update to the 3.x branch of the Popup Builder plugin to resolve the issue.
Exploit
Fix
RCE
SQL injection
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Popup Builder