Extension WordPress
Vulnérabilités CM Pop-Up – Create engaging popups to capture attention and boost interaction
Cette page rassemble les failles publiées pour CM Pop-Up – Create engaging popups to capture attention and boost interaction, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CM Pop-Up – Create engaging popups to capture attention and boost interaction
6 fiches
CM Pop-Up banners <= 1.8.4 – Missing Authorization
The CM Pop-Up – Create engaging popups to capture attention and boost interaction plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.4.…
*-1.8.4
1.8.5
16/07/2025
Multiple Plugins <= (Various Versions) – Reflected Cross-Site Scripting via cminds_free_guide Shortcode
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-1.7.5
1.7.6
25/11/2024
CM Pop-Up Banners <= 1.7.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The CM Pop-Up Banners for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via campaign data in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.7.2
1.7.3
22/08/2024
CM Popup Plugin for WordPress – Popup Maker <= 1.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The CM Popup Plugin for WordPress – Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width value in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping.…
*-1.6.5
1.6.6
01/07/2024
CM Pop-Up banners <= 1.5.10 – Authenticated (Subscriber+) SQL Injection via getStatistics
The CM Pop-Up banners plugin for WordPress is vulnerable to generic SQL Injection via the getStatistics function in versions up to, and including, 1.5.10 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation…
*-1.5.10
1.6.0
03/05/2023
CM Pop-Up banners <= 1.4.10 – Authenticated Stored Cross-Site Scripting
The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary…
*-1.4.10
1.5.0
27/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.