The Popup Builder WordPress plugin before 4.1.1 is vulnerable to SQL Injection and Reflected XSS via the sgpb-subscription-popup-id parameter.
id: CVE-2022-0479
info:
name: Popup Builder Plugin - SQL Injection and Cross-Site Scripting
aut
...