CVE-2019-14695: Sygnoos Popup Builder
Critical severity, CVSS 9.8. EPSS: 2.7% chance of exploitation in the next 30 days.
A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system via com/libs/Table.php because Subscribers Table ordering is mishandled.
Affected products
- Sygnoos Popup Builder: before 3.45 (fixed in 3.45)
Published 2019-08-06. Last modified 2026-06-17.