CVE-2024-2544: Sygnoos Popup Builder

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauthorized actions, such as deleting subscribers, and importing subscribers to conduct stored cross-site scripting attacks.

Affected products

  • Sygnoos Popup Builder: before 4.3.2 (fixed in 4.3.2)

Published 2024-06-15. Last modified 2026-06-17.