Extension WordPress

Vulnérabilités Popup Box (Developer) – Create Countdown, Coupon, Video, Contact Form Popups

Cette page rassemble les failles publiées pour Popup Box (Developer) – Create Countdown, Coupon, Video, Contact Form Popups, leurs plages de versions affectées et les correctifs signalés dans la base locale.

20Vulnérabilités
0Critiques
20Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Popup Box (Developer) – Create Countdown, Coupon, Video, Contact Form Popups

20 fiches

CVE-2026-57631 Moyenne · 4,9
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 6.0.1 – Authenticated (Administrator+) SQL Injection

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.0.1 due to insufficient escaping on the user supplied parameter and lack of…

Versions affectées

*-6.0.1

Correctif

6.0.2

Publication

26/06/2026

CVE-2026-54192 Moyenne · 6,1
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 6.2.9 – Reflected Cross-Site Scripting

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2.9 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-6.2.9

Correctif

6.3.0

Publication

16/06/2026

CVE-2025-15611 Élevée · 7,2
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups < 5.5.0 – Unauthenticated Stored Cross-Site Scripting

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

[*, 5.5.0)

Correctif

5.5.0

Publication

08/04/2026

CVE-2026-1165 Moyenne · 4,3
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box <= 6.1.1 – Cross-Site Request Forgery to Popup Status Change

The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather…

Versions affectées

*-6.1.1

Correctif

6.1.2

Publication

30/01/2026

CVE-2024-10861 Moyenne · 5,3
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 – Missing Authorization to Unauthenticated Limited Options Update

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including,…

Versions affectées

*-4.9.7

Correctif

4.9.8

Publication

15/11/2024

CVE-2024-9599 Moyenne · 4,4
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box <= 4.7.7 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.7 due to insufficient input sanitization and output…

Versions affectées

*-4.7.7

Correctif

4.7.8

Publication

31/10/2024

CVE-2024-3897 Moyenne · 5,3
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box – Best WordPress Popup Plugin <= 4.3.6 – Missing Authorization to Information Exposure

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_pb_create_author AJAX action in all versions up to, and including, 4.3.6. This…

Versions affectées

*-4.3.6

Correctif

4.3.7

Publication

24/04/2024

CVE-2023-6591 Moyenne · 6,6
Popup Box (Developer) – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box Business (7.0.0 – 7.9.0) and Developer (20.0.0 – 20.9.0) – Authenticated (Admin+) Stored Cross-Site Scripting

The Popup Box Business and Developer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 20.0.0 to 20.9.0 (Developer) and versions 7.0.0 to 7.9.0 (Business) due to insufficient input sanitization and output escaping.…

Versions affectées

[20.0.0, 20.9.0), [7.0.0, 7.9.0)

Correctif

7.9.0

Publication

22/01/2024

CVE-2023-5874 Moyenne · 4,4
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box <= 3.8.6 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 3.8.7 (exclusive) due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

[*, 3.8.7)

Correctif

3.8.7

Publication

13/11/2023

CVE-2023-5809 Moyenne · 4,4
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box <= 3.8.6 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 3.8.7 (exclusive) due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

[*, 3.8.7)

Correctif

3.8.7

Publication

13/11/2023

CVE-2023-5343 Moyenne · 4,4
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box – Best WordPress Popup Plugin <= 3.7.8 – Authenticated (Admin+) Stored Cross-Site Scripting

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-3.7.8

Correctif

3.7.9

Publication

27/10/2023

CVE-2023-4390 Moyenne · 4,4
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box <= 3.7.1 – Authenticated(Administrator+) Stored Cross-Site Scripting

The Popup Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

[*, 3.7.2)

Correctif

3.7.2

Publication

29/08/2023

Vulnérabilité Moyenne · 4,4
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup Box <= 3.7.0 – Authenticated(Administrator+) Stored Cross-Site Scripting

The Popup Box plugin is for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_html’ parameter in versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

[*, 3.7.1)

Correctif

3.7.1

Publication

18/08/2023

CVE-2023-27414 Moyenne · 5,4
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup box <= 3.4.4 – Reflected Cross-Site Scripting via 'ays_pb_tab' Parameter

The Popup box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_pb_tab' parameter in versions up to, and including, 3.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-3.4.4

Correctif

3.4.5

Publication

08/03/2023

CVE-2021-24458 Élevée · 8,8
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup box < 2.3.4 – Authenticated SQL Injection

The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection…

Versions affectées

[*, 2.3.4)

Correctif

2.3.4

Publication

29/06/2021

Vulnérabilité Moyenne · 6,1
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Popup box <= 2.3.3 – Cross-Site Scripting

The Popup box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 2.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.3.3

Correctif

2.3.4

Publication

29/06/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités