Extension WordPress

Vulnérabilités Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Cette page rassemble les failles publiées pour Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
0Critiques
19Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

19 fiches

CVE-2026-8848 Élevée · 7,2
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 – Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not…

Versions affectées

*-1.22.0

Correctif

1.23.0

Publication

08/07/2026

CVE-2025-9490 Moyenne · 6,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.20.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 1.20.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-1.20.6

Correctif

1.21.0

Publication

25/09/2025

CVE-2025-4205 Moyenne · 6,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.20.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via popupID Parameter

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-1.20.4

Correctif

1.20.5

Publication

03/06/2025

CVE-2025-24746 Moyenne · 6,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.20.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…

Versions affectées

*-1.20.2

Correctif

1.20.3

Publication

24/01/2025

CVE-2024-10583 Moyenne · 5,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to…

Versions affectées

*-1.20.2

Correctif

1.20.3

Publication

11/12/2024

CVE-2024-47358 Moyenne · 5,3
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.19.2 – Missing Authorization

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and…

Versions affectées

*-1.19.2

Correctif

1.20.0

Publication

30/09/2024

CVE-2024-5561 Moyenne · 4,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.19.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.19.0 due to insufficient…

Versions affectées

*-1.19.0

Correctif

1.19.1

Publication

19/08/2024

CVE-2024-7054 Moyenne · 6,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.19.0 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in all versions up to, and including, 1.19.0 due to…

Versions affectées

*-1.19.0

Correctif

1.19.1

Publication

19/08/2024

CVE-2024-2336 Moyenne · 6,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker – Popup for opt-ins, lead gen, & more <= 1.18.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and…

Versions affectées

*-1.18.2

Correctif

1.18.3

Publication

20/03/2024

CVE-2022-47597 Moyenne · 5,3
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.17.1 – Sensitive Data Exposure via debug log file

The Popup Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.17.1 due to the fact that the plugin generates a predictable name when creating debug log files. This can allow…

Versions affectées

*-1.17.1

Correctif

1.18.0

Publication

14/03/2023

CVE-2022-45819 Moyenne · 5,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.17.1 – Missing Authorization via save_popup_enabled_state

The Popup Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_popup_enabled_state function in versions up to, and including, 1.17.1. This makes it possible for authenticated attackers with…

Versions affectées

*-1.17.1

Correctif

1.18.0

Publication

09/03/2023

Vulnérabilité Moyenne · 4,3
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.18.0 – Cross-Site Request Forgery via init

The Popup Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.18.0. This is due to missing or incorrect nonce validation on the 'init' function. This makes it possible for unauthenticated…

Versions affectées

*-1.18.0

Correctif

1.18.1

Publication

08/03/2023

CVE-2022-3690 Moyenne · 5,5
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.16.10 – Authenticated (Administrator+) Stored Cross-Site Scripting

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.16.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and…

Versions affectées

*-1.16.10

Correctif

1.16.11

Publication

31/10/2022

CVE-2022-4381 Moyenne · 6,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.16.8 – Authenticated (Contributor+) Cross-Site Scripting

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup body content in versions up to, and including, 1.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-1.16.8

Correctif

1.16.9

Publication

26/09/2022

CVE-2022-4362 Moyenne · 6,4
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.16.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.16.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

Versions affectées

*-1.16.8

Correctif

1.16.9

Publication

23/09/2022

CVE-2022-1104 Moyenne · 5,5
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup Maker <= 1.16.4 – Authenticated (Admin+) Cross-Site Scripting

The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Cookie Time field in versions up to, and including, 1.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-1.16.4

Correctif

1.16.5

Publication

19/04/2022

CVE-2019-17574 Élevée · 7,5
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Popup-Maker <= 1.8.12 – Unauthenticated information disclosure

An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and…

Versions affectées

*-1.8.12

Correctif

1.8.13

Publication

14/10/2019

Vulnérabilité Élevée · 8,8
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Freemius SDK <= 2.2.3 – Missing Authorization to Arbitrary Options Update

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

[*, 1.8.3)

Correctif

1.8.3

Publication

25/02/2019

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités