Extension WordPress
Vulnérabilités Popup Box – Easily Create WordPress Popups
Cette page rassemble les failles publiées pour Popup Box – Easily Create WordPress Popups, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Popup Box – Easily Create WordPress Popups
5 fiches
Popup Box – Easily Create WordPress Popups <= 3.2.12 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and including, 3.2.12 due to insufficient input sanitization and output escaping…
*-3.2.12
3.2.13
17/02/2026
Popup Box <= 3.2.4 – Cross-Site Request Forgery
The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…
*-3.2.4
3.2.5
24/01/2025
Popup Box – new WordPress popup plugin <= 2.2.6 – Cross-Site Request Forgery
The Popup Box – new WordPress popup plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.6. This is due to missing or incorrect nonce validation on the popup-box page.…
*-2.2.6
2.2.7
11/04/2024
Multiple Wow-Company Plugins (Various Versions) — Reflected Cross-Site Scripting via 'page' parameter
Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
*-2.2.1
2.2.2
22/05/2023
Popup Box <= 2.1.2 – Authenticated Local File Inclusion
Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin
*-2.1.2
2.2
17/05/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.