Description
The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post.php, an authenticated attacker with minimal (subscriber-level) permissions can modify the plugin's settings to allow arbitrary roles (including subscribers) access to plugin functionality by setting the action parameter to sgpbSaveSettings, export a list of current newsletter subscribers by setting the action parameter to csv_file, or obtain system configuration information including webserver configuration and a list of installed plugins by setting the action parameter to sgpb_system_info.
Published: 2020-03-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-2656 The popup-builder plugin before 3.64.1 for WordPress allows information disclosure and settings modification, leading to in-scope privilege escalation via admin-post actions to com/classes/Actions.php. By sending a POST request to wp-admin/admin-post.php, an authenticated attacker with minimal (subscriber-level) permissions can modify the plugin's settings to allow arbitrary roles (including subscribers) access to plugin functionality by setting the action parameter to sgpbSaveSettings, export a list of current newsletter subscribers by setting the action parameter to csv_file, or obtain system configuration information including webserver configuration and a list of installed plugins by setting the action parameter to sgpb_system_info.
History

Wed, 07 May 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Sygnoos popup Builder
CPEs cpe:2.3:a:sygnoos:popup-builder:*:*:*:*:*:wordpress:*:* cpe:2.3:a:sygnoos:popup_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Sygnoos popup-builder
Sygnoos popup Builder

Subscriptions

Sygnoos Popup Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T10:58:39.016Z

Reserved: 2020-03-06T00:00:00.000Z

Link: CVE-2020-10195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-13T16:15:12.207

Modified: 2025-05-07T15:42:53.850

Link: CVE-2020-10195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses