Extension WordPress
Vulnérabilités Popup Like box – Page Plugin
Cette page rassemble les failles publiées pour Popup Like box – Page Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Popup Like box – Page Plugin
5 fiches
Popup Like box <= 3.7.7 – Missing Authorization
The Popup Like box plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.7.7. This makes it possible for unauthenticated attackers to perform an…
*-3.7.7
3.7.8
01/03/2026
Popup Like box – Page <= 3.7.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Popup Like box – Page Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.7.2 due to insufficient input sanitization and output escaping. This makes it…
*-3.7.2
3.7.3
10/04/2024
Popup Like box <= 3.6.0 – Reflected Cross-Site Scripting
The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
[*, 3.6.1)
3.6.1
07/03/2022
Popup Like box – Page Plugin <= 3.5.2 – Cross-Site Scripting
The "Popup Like box – Page Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 3.5.2 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.5.2
3.5.3
29/06/2021
Popup Like box – Page Plugin < 3.5.3 – SQL Injection
The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to…
*-3.5.2
3.5.3
29/06/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.