The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion issue. Furthermore, since the beginning of the string can be controlled, the issue can lead to RCE vulnerability via wrappers such as PHAR
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-02-21T10:45:51
Updated: 2024-08-03T19:56:09.873Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-25082
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-21T11:15:08.757
Modified: 2024-11-21T05:54:18.970
Link: CVE-2021-25082
Redhat
No data.