CVE-2025-14314

8.5

Roxnor · PopupKit

Roxnor PopupKit contains a blind SQL injection vulnerability in the popup-builder-block component that allows authenticated attackers to extract data from the database.

Executive summary

A blind SQL injection vulnerability in Roxnor PopupKit version 2.1.5 and earlier poses a high risk of sensitive data exposure for affected WordPress environments.

Vulnerability

The plugin fails to properly sanitize user-supplied input within the popup-builder-block component, leading to a blind SQL injection. The CVSS vector (PR:L) indicates that an authenticated user with low privileges can trigger this flaw to perform unauthorized database operations.

Business impact

Successful exploitation of this vulnerability allows an attacker to perform blind SQL injection, potentially leading to the unauthorized exfiltration of sensitive information from the underlying database. With a CVSS score of 8.5, this high-severity flaw represents a significant risk to data confidentiality and integrity, which could result in severe regulatory non-compliance and reputational damage.

Remediation

Immediate Action: Since no specific patch version is currently confirmed, administrators should monitor the official Roxnor repository for updates and disable the PopupKit plugin if it is not business-critical.

Proactive Monitoring: Security teams should monitor database logs for anomalous query patterns, specifically those containing SQL syntax or unusual function calls originating from the application layer.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common SQL injection patterns targeting WordPress plugins.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the high CVSS score of 8.5, organizations using Roxnor PopupKit must treat this vulnerability with urgency. Until a vendor-supplied patch is released and applied, administrators should restrict access to the affected features or deactivate the plugin to prevent potential exploitation by authenticated users.

More Roxnor CVEs

Sources

Originally found and disclosed by 0xd4rk5id3 | Patchstack Bug Bounty Program, per the CVE Program record.