Extension WordPress
Vulnérabilités Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
Cette page rassemble les failles publiées pour Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
19 fiches
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 – Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not…
*-1.22.0
1.23.0
08/07/2026
Popup Maker <= 1.20.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.20.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-1.20.6
1.21.0
25/09/2025
Popup Maker <= 1.20.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via popupID Parameter
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-1.20.4
1.20.5
03/06/2025
Popup Maker <= 1.20.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-1.20.2
1.20.3
24/01/2025
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to…
*-1.20.2
1.20.3
11/12/2024
Popup Maker <= 1.19.2 – Missing Authorization
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and…
*-1.19.2
1.20.0
30/09/2024
Popup Maker <= 1.19.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.19.0 due to insufficient…
*-1.19.0
1.19.1
19/08/2024
Popup Maker <= 1.19.0 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in all versions up to, and including, 1.19.0 due to…
*-1.19.0
1.19.1
19/08/2024
Popup Maker – Popup for opt-ins, lead gen, & more <= 1.18.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and…
*-1.18.2
1.18.3
20/03/2024
Popup Maker <= 1.17.1 – Sensitive Data Exposure via debug log file
The Popup Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.17.1 due to the fact that the plugin generates a predictable name when creating debug log files. This can allow…
*-1.17.1
1.18.0
14/03/2023
Popup Maker <= 1.17.1 – Missing Authorization via save_popup_enabled_state
The Popup Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_popup_enabled_state function in versions up to, and including, 1.17.1. This makes it possible for authenticated attackers with…
*-1.17.1
1.18.0
09/03/2023
Popup Maker <= 1.18.0 – Cross-Site Request Forgery via init
The Popup Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.18.0. This is due to missing or incorrect nonce validation on the 'init' function. This makes it possible for unauthenticated…
*-1.18.0
1.18.1
08/03/2023
Popup Maker <= 1.16.10 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.16.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…
*-1.16.10
1.16.11
31/10/2022
Popup Maker <= 1.16.8 – Authenticated (Contributor+) Cross-Site Scripting
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup body content in versions up to, and including, 1.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-1.16.8
1.16.9
26/09/2022
Popup Maker <= 1.16.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.16.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-1.16.8
1.16.9
23/09/2022
Popup Maker <= 1.16.4 – Authenticated (Admin+) Cross-Site Scripting
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Cookie Time field in versions up to, and including, 1.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-1.16.4
1.16.5
19/04/2022
Popup-Maker <= 1.8.12 – Unauthenticated information disclosure
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and…
*-1.8.12
1.8.13
14/10/2019
Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…
[*, 1.8.3)
1.8.3
25/02/2019
Popup Maker < 1.6.5 – Reflected Cross-Site Scripting
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[*, 1.6.5)
1.6.5
24/07/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.