PT-2020-20425 · WordPress · Popup Builder

Yeraisci

·

Published

2020-02-17

·

Updated

2021-07-21

·

CVE-2020-9006

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Popup Builder plugin versions 2.2.8 through 2.6.7.6
Description The issue allows for SQL injection via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable in the sgImportPopups function in sg popup ajax.php. This enables the creation of an arbitrary WordPress Administrator account, potentially leading to Remote Code Execution since Administrators can run PHP code on WordPress instances.
Recommendations For versions 2.2.8 through 2.6.7.6, update to the 3.x branch of the Popup Builder plugin to resolve the issue.

Exploit

Fix

RCE

SQL injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9006

Affected Products

Popup Builder