The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1.3. This is due to insufficient escaping on the 'id' parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Metrics
Affected Vendors & Products
References
History
Thu, 09 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 09 Oct 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Roxnor
Roxnor popup Builder Woocommerce Woocommerce woocommerce Wordpress Wordpress wordpress |
|
Vendors & Products |
Roxnor
Roxnor popup Builder Woocommerce Woocommerce woocommerce Wordpress Wordpress wordpress |
Thu, 09 Oct 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1.3. This is due to insufficient escaping on the 'id' parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |
Title | Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id' | |
Weaknesses | CWE-89 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-09T08:23:17.221Z
Updated: 2025-10-09T15:06:58.535Z
Reserved: 2025-09-22T22:58:28.462Z
Link: CVE-2025-10862

Updated: 2025-10-09T15:05:09.170Z

Status : Awaiting Analysis
Published: 2025-10-09T09:15:45.080
Modified: 2025-10-09T15:50:04.013
Link: CVE-2025-10862

No data.