Extension WordPress

Vulnérabilités CM Pop-Up – Create engaging popups to capture attention and boost interaction

Cette page rassemble les failles publiées pour CM Pop-Up – Create engaging popups to capture attention and boost interaction, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CM Pop-Up – Create engaging popups to capture attention and boost interaction

6 fiches

CVE-2024-11202 Moyenne · 6,1
CM Pop-Up – Create engaging popups to capture attention and boost interaction

Multiple Plugins <= (Various Versions) – Reflected Cross-Site Scripting via cminds_free_guide Shortcode

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…

Versions affectées

*-1.7.5

Correctif

1.7.6

Publication

25/11/2024

CVE-2024-5799 Moyenne · 6,4
CM Pop-Up – Create engaging popups to capture attention and boost interaction

CM Pop-Up Banners <= 1.7.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The CM Pop-Up Banners for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via campaign data in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-1.7.2

Correctif

1.7.3

Publication

22/08/2024

CVE-2024-5004 Moyenne · 6,4
CM Pop-Up – Create engaging popups to capture attention and boost interaction

CM Popup Plugin for WordPress – Popup Maker <= 1.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting

The CM Popup Plugin for WordPress – Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width value in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping.…

Versions affectées

*-1.6.5

Correctif

1.6.6

Publication

01/07/2024

CVE-2023-30750 Élevée · 8,8
CM Pop-Up – Create engaging popups to capture attention and boost interaction

CM Pop-Up banners <= 1.5.10 – Authenticated (Subscriber+) SQL Injection via getStatistics

The CM Pop-Up banners plugin for WordPress is vulnerable to generic SQL Injection via the getStatistics function in versions up to, and including, 1.5.10 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation…

Versions affectées

*-1.5.10

Correctif

1.6.0

Publication

03/05/2023

Vulnérabilité Moyenne · 6,4
CM Pop-Up – Create engaging popups to capture attention and boost interaction

CM Pop-Up banners <= 1.4.10 – Authenticated Stored Cross-Site Scripting

The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary…

Versions affectées

*-1.4.10

Correctif

1.5.0

Publication

27/03/2020

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités