An unknown person discovered and reported this SQL Injection vulnerability in WordPress Popup Builder Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 4.0.7.