← back
CVE-2021-25082observed exploitationCWE-22

Popup Builder < 4.0.7 - LFI to RCE

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 5.2%
from disclosure to weapon
Published on NVDFeb 21
VulnCheck+301d
exploitation probability
5.2%top 8% of all CVEs
observed exploitation
yesVulnCheck
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR