Extension WordPress

Vulnérabilités Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

Cette page rassemble les failles publiées pour Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
8,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

7 fiches

CVE-2025-14895 Moyenne · 5,4
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

PopupKit <= 2.2.0 – Missing Authorization to Sensitive Information Disclosure and Data Deletion

The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not properly verifying that a user is authorized to access the /popup/logs REST API…

Versions affectées

*-2.2.0

Correctif

2.2.1

Publication

09/02/2026

CVE-2025-13192 Élevée · 8,2
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

Popup builder with Gamification <= 2.2.0 – Unauthenticated SQL Injection via Multiple REST API Endpoints

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to generic SQL Injection via the multiple REST API endpoints in all versions up to, and including, 2.2.0 due to insufficient…

Versions affectées

*-2.2.0

Correctif

2.2.1

Publication

04/02/2026

CVE-2025-14441 Moyenne · 4,3
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

Popupkit <= 2.2.0 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data Deletion

The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on the DELETE `/subscribers` REST API endpoint in all versions up to, and including, 2.2.0. This is due to the `permission_callback` only…

Versions affectées

*-2.2.0

Correctif

2.2.1

Publication

05/01/2026

CVE-2025-69026 Moyenne · 4,3
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

PopupKit <= 2.1.5 – Authenticated (Subscriber+) Information Exposure

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.5. This makes it possible for authenticated attackers, with Subscriber-level…

Versions affectées

*-2.1.5

Correctif

2.2.1

Publication

29/12/2025

CVE-2025-14314 Moyenne · 6,5
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

PopupKit <= 2.1.5 – Authenticated (Subscriber+) SQL Injection

The PopupKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-2.1.5

Correctif

2.2.0

Publication

21/11/2025

CVE-2025-10861 Élevée · 7,5
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.4 – Unauthenticated Server-Side Request Forgery

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.1.4. This is due to insufficient validation on the URLs…

Versions affectées

*-2.1.4

Correctif

2.1.5

Publication

23/10/2025

CVE-2025-10862 Élevée · 7,5
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 – Unauthenticated SQL Injection via 'id'

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1.3. This is due to insufficient escaping on the 'id' parameter…

Versions affectées

*-2.1.3

Correctif

2.1.4

Publication

08/10/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités