Sygnoos develops WordPress plugins including a popup builder and social media sharing components that extend the functionality of widely deployed WordPress installations. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the web-application and WordPress-ecosystem context of these products. The recurring weakness classes—including cross-site scripting, SQL injection, untrusted deserialization, cross-site request forgery, and sensitive information exposure—are characteristic of server-side PHP plugins that handle user input and interact with WordPress databases and third-party services. Defenders should treat updates to these plugins as high-priority, particularly on internet-facing WordPress sites, and audit configurations for data-handling practices around forms and social integrations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sygnoos over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0479CRITICAL The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admi | Mar 28, 2022 | 9.8 | 58 | NO | YES |
CVE-2021-25082HIGH The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it in a require statement, leading to a Local File Inclusion iss | Feb 21, 2022 | 8.8 | 41 | NO | YES |
CVE-2020-9006CRITICAL The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacke | Feb 17, 2020 | 9.8 | 33 | NO | NO |
CVE-2023-6000MEDIUM The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them, which could lead to Stored XSS | Jan 1, 2024 | 6.1 | 32 | NO | YES |
CVE-2022-0228HIGH The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters before using them in a SQL statement in the admin dashboard, | Feb 21, 2022 | 7.2 | 31 | NO | YES |
CVE-2019-14695CRITICAL A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to e | Aug 6, 2019 | 9.8 | 31 | NO | NO |
CVE-2024-1685HIGH The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through | Mar 16, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-2721HIGH Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through | Mar 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-2541HIGH The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes it | Aug 29, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-6696HIGH The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capabili | Jun 15, 2024 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sygnoos.
Media articles that mention a CVE ID that affects a product developed by Sygnoos — matched by CVE ID, not by vendor name.