What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder easy-notify-lite allows PHP Local File Inclusion.This issue affects Popup Builder: from n/a through <= 1.1.35.
Explanation of Vulnerability in Simple Terms
02Summary
Popup Builder versions up to 1.1.35 contain a code injection vulnerability that allows authenticated users with low privileges to execute arbitrary code on the site. The vulnerability requires network access and high attack complexity, but does not require user interaction. An attacker can read sensitive data, modify site content, or disrupt service availability.
What an attacker can do
03Attacker Capabilities
Execute arbitrary code on the site, read sensitive data, modify content, or cause service disruption.
Potential impact on your site
04Site Impact
A low-privilege user account (subscriber, contributor, or equivalent) can run malicious code with full site access.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege authenticated account; network access required.
Key dates
06Disclosure timeline
April 24, 2025
CVE published
May 12, 2026
Record updated