Popup Builder WordPress plugin before 4.0.7 contains a local file inclusion caused by unsanitized 'sgpb_type' parameter in require statement, letting attackers include arbitrary local files or execute code via wrappers like PHAR, exploit requires attacker to control 'sgpb_type' parameter.
id: CVE-2021-25082
info:
name: WordPress Popup Builder < 4.0.7 - Remote Code Execution
author:
...