CVE-2022-29445 MEDIUM

CVE-2022-29445: WordPress Popup Box plugin <= 2.1.2 - Authenticated Local File Inclusion (LFI) vulnerability

Vendor Wow-Company
Product Popup Box (WordPress plugin)
Published May 18, 2022
Last update April 28, 2026

CVSS base score

6.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin <= 2.1.2 at WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

An authenticated administrator with high privileges can trigger arbitrary code execution in the Popup Box plugin by uploading a malicious file. The vulnerability requires the attacker to have admin-level access and the site owner to interact with a crafted request. This allows complete compromise of the WordPress installation.

What an attacker can do

03Attacker Capabilities

Run arbitrary code on the WordPress site with full admin privileges.

Potential impact on your site

04Site Impact

An admin account compromise could lead to complete site takeover, data theft, or malware injection affecting all site visitors.

Conditions required to exploit

05Prerequisites

Attacker must have administrator access and trick a site owner into clicking a malicious link or visiting a crafted page.

Key dates

06Disclosure timeline

May 18, 2022 CVE published
April 28, 2026 Record updated