Extension WordPress
Vulnérabilités Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
Cette page rassemble les failles publiées pour Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
6 fiches
Essentialplugin Plugins (Various Versions) – Injected Backdoor
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they…
2.9.1
2.9.1.1
09/04/2026
Popup Anything <= 2.8.0 – Missing Authorization
The Popup Anything – Popup for opt-ins and Lead Generation Conversions plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the popupaoc_render_popup_preview() function in all versions up to, and including,…
*-2.8.0
2.8.1
16/04/2024
Multiple WPOnlineSupport Plugins <= (Various Versions) – Missing Authorization to Notice Dismissal
Multiple WPOnlineSupport plugins for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on the wpos_anylc_admin_init_process() function hooked via admin_init in various versions. This makes it possible for unauthenticated attackers to dismiss a…
*-2.7
2.8
16/08/2023
WP OnlineSupport, Essential Plugin Popup Anything <= 2.2.1 – Cross Site Request Forgery
The WP OnlineSupport, Essential Plugin Popup Anything plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.1. This is due to missing nonce validation on the popupaoc_register_settings() function. This makes it possible…
[*, 2.2.2)
2.2.2
28/03/2023
Popup Anything – A Marketing Popup and Lead Generation Conversions <= 2.1.6 – Reflected Cross-Site Scripting
The Popup Anything – A Marketing Popup and Lead Generation Conversions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a custom key parameter in versions up to, and including, 2.1.6 due to insufficient input sanitization and…
*-2.1.6
2.1.7
04/07/2022
Popup Anything <= 2.0.3 – Contributor+ Stored Cross-Site Scripting
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
*-2.0.3
2.0.4
25/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.