Popup Builder < 4.0.7 - LFI to RCE
40Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 5.2%
from disclosure to weapon
Published on NVDFeb 21
VulnCheck+301d
exploitation probability
5.2%top 8% of all CVEs
observed exploitation
yesVulnCheck
The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR