{"error":0,"message":null,"data":{"name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder","plugin":"popup-maker","link":"https:\/\/wordpress.org\/plugins\/popup-maker\/","latest":"1789088040","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"d427e9514408e9ee66ea1e7ef2dd76b8c267e527928f2d56aba5bde671f59dd3","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.8.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-17574","name":"CVE-2019-17574","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-17574","description":"[en] An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the \"support debug text file\").","date":"2019-10-14"},{"id":"c6cb896cb63294fd84f3c1a4d021f3adeb25712c","name":"Popup-Maker <= 1.8.12 - Unauthenticated information disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1812-unauthenticated-information-disclosure","description":"An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the \"support debug text file\").","date":"2019-10-14"},{"id":"f9eb8bf2-85cd-413d-8234-fcd3c0456894","name":"Popup-Maker &lt; 1.8.12 - Multiple Vulnerabilities","link":"https:\/\/wpscan.com\/vulnerability\/f9eb8bf2-85cd-413d-8234-fcd3c0456894","description":"An attacker can partially control the arguments of the do_action, during the initialization of the PUM_Site . Because of this, an attacker can call any method which contains an action starting from popmake_ or pum_ . This will lead to successful execution of functions which do not require arguments (e.g: PUM_Admin_Tools::sysinfo_download or PUM_Admin_Tools::sysinfo_display) or require one argument as an array.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"n","score":"9.1","severity":"c","exploitable":"3.9","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:N","score":"9.1","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"3.9","impact":"5.2"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}]}},{"uuid":"e3bd2e1fd05be8e0820e23b59644432192874c7990b52c494fa37643062ea6e6","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.6.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2017-2284","name":"CVE-2017-2284","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2017-2284","description":"[en] Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","date":"2017-08-02"},{"id":"JVNDB-2017-000181","name":"WordPress plugin \"Popup Maker\" vulnerable to cross-site scripting","link":"http:\/\/jvndb.jvn.jp\/jvndb\/JVNDB-2017-000181","description":"The WordPress plugin \"Popup Maker\" provided by Popup Maker contains a reflected cross-site scripting vulnerability (CWE-79).  Chris Liu reported this vulnerability to IPA. JPCERT\/CC coordinated with the developer under Information Security Early Warning Partnership.","date":"2017-07-24"},{"id":"fdc8374a2303bb808a0caf8fe0b182aeb4f64ad1","name":"WordPress Popup Maker plugin <=1.6.4 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-6-4-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability in WordPress Popup Maker plugin 1.6.4 and earlier versions allows an attacker to inject arbitrary web script or HTML.\nUpdate WordPress Popup Maker plugin to the latest available version (at least 1.6.5)","date":"2017-07-25"},{"id":"8e8e78d73e72fef97046c6e3f33dae331e7284a9","name":"Popup Maker < 1.6.5 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-165-reflected-cross-site-scripting","description":"Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","date":"2017-07-24"},{"id":"400232f1-9ace-4b80-bf97-4ecf394b12f5","name":"Popup Maker &lt;= 1.6.4 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/400232f1-9ace-4b80-bf97-4ecf394b12f5","description":"The Popup Maker &ndash; Popup Forms, Opt-ins &amp; More WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"811be2b2382a43a36b7f323903c1feb32bc7a7b81995229dcbab629b33ea0bd2","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.16.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.16.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-1104","name":"CVE-2022-1104","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-1104","description":"[en] The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed","date":"2022-05-09"},{"id":"b4d7697973722866232082f95d4b91ec81bea44f","name":"WordPress Popup Maker plugin <= 1.16.4 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-16-4-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by Roel van Beurden in WordPress Popup Maker plugin (versions <= 1.16.4).","date":"2022-04-12"},{"id":"edd34c45da8b7fad2c069332a642fa650d2deec4","name":"Popup Maker <= 1.16.4 - Authenticated (Admin+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1164-authenticated-admin-cross-site-scripting","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Cookie Time field in versions up to, and including, 1.16.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative access to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2022-04-19"},{"id":"4d4709f3-ad38-4519-a24a-73bc04b20e52","name":"Popup Maker &lt; 1.16.5 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/4d4709f3-ad38-4519-a24a-73bc04b20e52","description":"The plugin does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"43a9fdc572d7db0d17a11f07df05f6e635f707b60d2f235140c693660fa49fb3","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6ff37c2e-e21d-4abc-bafe-8ca6a2c1ed76","name":"Freemius Library &lt; 2.2.4 - Subscriber+ Arbitrary Option Update","link":"https:\/\/wpscan.com\/vulnerability\/6ff37c2e-e21d-4abc-bafe-8ca6a2c1ed76","description":"The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options","date":null}],"impact":[]},{"uuid":"02a52dccd2efd5d187379db6f34dd2a61e39471d0ac95a5af5bfe1064f3284f4","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.16.11","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.16.11","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-3690","name":"CVE-2022-3690","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-3690","description":"[en] The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins","date":"2022-11-21"},{"id":"daa2087e46e9f486784ee8743dc19b826a10c77e","name":"WordPress Popup Maker plugin <= 1.16.10 - Auth. Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-16-10-auth-stored-cross-site-scripting-xss-vulnerability","description":"Auth. Stored Cross-Site Scripting (XSS) vulnerability discovered by c3p0d4y in WordPress Popup Maker plugin (versions <= 1.16.10).\nUpdate the WordPress Popup Maker plugin to the latest available version (at least 1.16.11).","date":"2022-10-31"},{"id":"ffc8474452a373587f300bbfa93b55dcf8e1e6c2","name":"Popup Maker <= 1.16.10 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-11610-authenticated-administrator-stored-cross-site-scripting","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.16.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-10-31"},{"id":"725f6ae4-7ec5-4d7c-9533-c9b61b59cc2b","name":"Popup Maker &lt; 1.16.11 - Admin+ Stored Cross Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/725f6ae4-7ec5-4d7c-9533-c9b61b59cc2b","description":"The plugin does not sanitise and escape some of its Popup options, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0f54f384019dd7564b8c748aa006e02cc65b9ea6dbe6a1caeee77ce45a14e88c","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.16.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.16.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"138af3136b67b000f20b74ce5d3071ef77150667","name":"Popup Maker <= 1.16.8 - Authenticated (Contributor+) Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1168-authenticated-contributor-cross-site-scripting","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup body content in versions up to, and including, 1.16.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-09-26"},{"id":"CVE-2022-4381","name":"CVE-2022-4381","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4381","description":"[en] The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks","date":"2023-01-02"},{"id":"315db4a2d585ad62c897c3da8c5d1823877bdf7b","name":"WordPress  Popup Maker Plugin  < 1.16.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-16-9-auth-stored-cross-site-scripting-xss-vulnerability-2","description":"Update the WordPress Popup Maker plugin to the latest available version (at least 1.16.9).\nAn Doan discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Popup Maker Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.16.9.","date":"2023-09-23"},{"id":"8bf8ebe8-1063-492d-a0f9-2f824408d0df","name":"Popup Maker &lt; 1.16.9 - Contributor+ Stored XSS via Subscription Form","link":"https:\/\/wpscan.com\/vulnerability\/8bf8ebe8-1063-492d-a0f9-2f824408d0df","description":"The plugin does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9626bb5e4f26ded2225f8f4791c971380a6b8aefc896da268b8d048b4f3f2c20","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.8.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7e57cd4f4859826de00a8e2b09ee24fb7f2d824b","name":"Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/freemius-sdk-223-missing-authorization-to-arbitrary-options-update","description":"The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and potentially take over the site.","date":"2019-02-25"}],"impact":[]},{"uuid":"42981927581121e0078a7f93e0f6258311758dc343101d938418ec2a2a75d311","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.16.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.16.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-4362","name":"CVE-2022-4362","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4362","description":"[en] The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks","date":"2023-01-02"},{"id":"f771e4ef94a409fca4bcea887df57af6625b0104","name":"Popup Maker <= 1.16.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1168-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.16.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page","date":"2022-09-23"},{"id":"4068f036980e868dba0a3f85bf5fd98650b927b9","name":"WordPress  Popup Maker Plugin  < 1.16.9 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-16-9-auth-stored-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Popup Maker plugin to the latest available version (at least 1.16.9).\nTin Pham aka TF1T discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Popup Maker Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.16.9.","date":"2023-09-23"},{"id":"2660225a-e4c8-40f2-8c98-775ef2301212","name":"Popup Maker &lt; 1.16.9 - Contributor+ Stored XSS via Shortcode","link":"https:\/\/wpscan.com\/vulnerability\/2660225a-e4c8-40f2-8c98-775ef2301212","description":"The plugin does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ab77a7f6e06f5c93034909c2038bea576b3ef2970c93c2c59e5392d1df545f91","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.18.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"474920b53a3f66864948949f8baa9e89ab06023b","name":"Popup Maker <= 1.18.0 - Cross-Site Request Forgery via init","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1180-cross-site-request-forgery-via-init","description":"The Popup Maker plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.18.0. This is due to missing or incorrect nonce validation on the 'init' function. This makes it possible for unauthenticated attackers to flush the popup cache via forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-03-08"}],"impact":[]},{"uuid":"0963b352c4b272db0bbaca91a1cca077b2042d7471c628f3fbd6984e6ceacb54","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.18.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c5aa28f4a3ad15c66fb8396a3d2622eb4d13577b","name":"WordPress  Popup Maker Plugin  <= 1.18.0 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-18-0-cross-site-request-forgery-vulnerability","description":"Update the WordPress Popup Maker plugin to the latest available version (at least 1.18.1).\nUnknown discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Popup Maker Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 1.18.1.","date":"2023-03-09"}],"impact":[]},{"uuid":"e31809614352a94950ea691cffd0c86ae8eb893fd460a8776e9da49899e56724","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.18.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-47597","name":"CVE-2022-47597","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-47597","description":"[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Popup Maker Popup Maker \u2013 Popup for opt-ins, lead gen, & more.This issue affects Popup Maker \u2013 Popup for opt-ins, lead gen, & more: from n\/a through 1.17.1.","date":"2023-12-20"},{"id":"e5d2a5637793224081becc227c8fc7407ef37b29","name":"WordPress  Popup Maker Plugin  <= 1.17.1 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-17-1-unauth-access-to-debug-log","description":"Update the WordPress Popup Maker plugin to the latest available version (at least 1.18.0).\nrezaduty discovered and reported this Sensitive Data Exposure vulnerability in WordPress Popup Maker Plugin.  This vulnerability has been fixed in version 1.18.0.","date":"2023-03-14"},{"id":"3dde717cd1009130b0e5abd584b38bbd940bc230","name":"Popup Maker <= 1.17.1 - Sensitive Data Exposure via debug log file","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1171-sensitive-data-exposure-via-debug-log-file","description":"The Popup Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.17.1 due to the fact that the plugin generates a predictable name when creating debug log files. This can allow unauthenticated attackers to view log files.","date":"2023-03-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}]}},{"uuid":"30df270480479338e3822d7f8b4f8796395dc319570144428bed28ed820999e4","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.18.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-45819","name":"CVE-2022-45819","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-45819","description":"[en] Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n\/a through 1.17.1.","date":"2024-12-13"},{"id":"9b8cf93276c560bb3a58c20a61502b924a2cd4c0","name":"WordPress  Popup Maker Plugin  <= 1.17.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-17-1-broken-access-control-vulnerability","description":"Update the WordPress Popup Maker plugin to the latest available version (at least 1.18.0).\nLana Codes discovered and reported this Broken Access Control vulnerability in WordPress Popup Maker Plugin.  This vulnerability has been fixed in version 1.18.0.","date":"2023-03-13"},{"id":"0ebb18dafed5d01e35c1973568ea0de51a748736","name":"Popup Maker <= 1.17.1 - Missing Authorization via save_popup_enabled_state","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1171-missing-authorization-via-save-popup-enabled-state","description":"The Popup Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_popup_enabled_state function in versions up to, and including, 1.17.1. This makes it possible for authenticated attackers with contributor-level access, and above, to enable and disable popups even when they do not have the right to edit those popups.","date":"2023-03-09"},{"id":"EUVD-2022-48673","name":"EUVD-2022-48673","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2022-48673","description":"Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n\/a through 1.17.1.","date":"2024-12-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"u","c":"l","i":"n","a":"n","score":"3.5","severity":"l","exploitable":"2.1","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:L\/I:N\/A:N","score":"3.5","severity":"low","av":"network","ac":"low","pr":"low","ui":"required","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.1","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"416db9624efc0631b915e2ed87bba8417dbe7b6e87a84406deb69a257bf74cd2","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.10.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-33999","name":"CVE-2023-33999","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-33999","description":"[en] Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS.\n\nThis issue affects WP Mail Log: from n\/a through 1.0.2.","date":"2026-06-11"},{"id":"c1fb5dd9342f13923ddf9b187876b8b3cb7dea4c","name":"WordPress  Popup Maker Plugin  <= 1.9.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-9-2-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Popup Maker plugin to the latest available version (at least 1.10.0).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Popup Maker Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.10.0.","date":"2023-07-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6aa0045f51388913986370607ad2e70714679b8427e68a785165f5a283f4c9fa","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.18.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2336","name":"CVE-2024-2336","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2336","description":"[en] The Popup Maker \u2013 Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-04-09"},{"id":"c8313f7513ce2ea60d5d6778fad4c19df5849bf4","name":"Popup Maker \u2013 Popup for opt-ins, lead gen, & more <= 1.18.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-popup-for-opt-ins-lead-gen-more-1182-authenticated-contributor-stored-cross-site-scripting","description":"The Popup Maker \u2013 Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-20"},{"id":"4149f095c9b65765ee743d3c9d0e8fd097dee727","name":"WordPress  Popup Maker Plugin    <= 1.18.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-18-2-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Popup Maker plugin to the latest available version (at least 1.18.3).\nTim Coen discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Popup Maker Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.18.3.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"673562fe-e2be-407b-b6ef-b706f9ac769a","name":"Popup Maker &ndash; Popup for opt-ins, lead gen, &amp; more &lt; 1.18.3 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/673562fe-e2be-407b-b6ef-b706f9ac769a","description":"The plugin does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e04696d53aaa4610b11688168063f8b5d66226c84d93587db1a6cf9d39f16532","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.19.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.19.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-7054","name":"CVE-2024-7054","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-7054","description":"[en] The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018close_text\u2019 parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-08-20"},{"id":"3491f0250a76a8d42891fe2ade2161dc15fc1636","name":"WordPress Popup Maker Plugin <= 1.19.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-19-0-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Popup Maker Plugin <= 1.19.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Popup Maker<\/p><p>Link: https:\/\/wordpress.org\/plugins\/popup-maker\/#developers<\/p><p>Affected Version <= 1.19.0<\/p><p>Fixed in version 1.19.1 <\/p>","date":"2024-08-20"},{"id":"e423ef26727e1edfdc0aa49fc0b6bb2da602be9d","name":"Popup Maker <= 1.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1190-authenticated-contributor-stored-cross-site-scripting","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018close_text\u2019 parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-08-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"eead4e638b77633b345bf90b1037b309397110596ac4ca9a998d7d1314a4c631","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.19.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.19.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5561","name":"CVE-2024-5561","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5561","description":"[en] The Popup Maker  WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":"2024-09-09"},{"id":"7864307343ade749941334cac48a0ff3986acc94","name":"WordPress Popup Maker Plugin < 1.19.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-19-1-admin-stored-xss-vulnerability","description":"<p>WordPress Popup Maker Plugin < 1.19.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Popup Maker<\/p><p>Link: https:\/\/wordpress.org\/plugins\/popup-maker\/#developers<\/p><p>Affected Version < 1.19.1<\/p><p>Fixed in version 1.19.1 <\/p>","date":"2024-09-09"},{"id":"ad512ceb01fc864305e4ebeeca0bd593059d4833","name":"Popup Maker <= 1.19.0 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1190-authenticated-admin-stored-cross-site-scripting","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-08-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fffd73129b1bcb5dff7ea3eb0d5cebe5072452c55f352806b41da84470fee78b","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.20.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-47358","name":"CVE-2024-47358","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-47358","description":"[en] Missing Authorization vulnerability in Daniel Iser Popup Maker popup-maker.This issue affects Popup Maker: from n\/a through <= 1.19.2.","date":"2024-11-01"},{"id":"4d83f81e2c441f4e6230f742046ed0921b58150c","name":"WordPress Popup Maker Plugin <= 1.19.2 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-19-2-broken-access-control-vulnerability","description":"<p>WordPress Popup Maker Plugin <= 1.19.2 is vulnerable to Broken Access Control<\/p><p>Software: Popup Maker<\/p><p>Link: https:\/\/wordpress.org\/plugins\/popup-maker\/#developers<\/p><p>Affected Version <= 1.19.2<\/p><p>Fixed in version 1.20.0 <\/p>","date":"2024-09-30"},{"id":"d2d21883886066d92dc465d406da63321a884130","name":"Popup Maker <= 1.19.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1192-missing-authorization","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.19.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2024-09-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"71281bf4e26031d5a35320636d11b094908f0b63dd936bff3e35b251d6b0215d","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.20.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10583","name":"CVE-2024-10583","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10583","description":"[en] The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018post_title\u2019 parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-12"},{"id":"bfda2c0322bae88c72e9fecc2c084451d15ab964","name":"Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-boost-sales-conversions-optins-subscribers-with-the-ultimate-wp-popups-builder-1202-authenticated-contributor-stored-cross-site-scripting","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018post_title\u2019 parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-11"},{"id":"EUVD-2024-33515","name":"EUVD-2024-33515","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-33515","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018post_title\u2019 parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-12-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0f75b59bc5b61a89d7be202edd7c2cca0dfaac8501ab8af8390fdba1c7d1ab62","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.20.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-24746","name":"CVE-2025-24746","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24746","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Popup Maker popup-maker allows Stored XSS.This issue affects Popup Maker: from n\/a through <= 1.20.2.","date":"2025-01-24"},{"id":"461ff4464d984c5da1d7bb189a170c01dee5b660","name":"WordPress Popup Maker Plugin <= 1.20.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/popup-maker\/vulnerability\/wordpress-popup-maker-plugin-1-20-2-cross-site-scripting-xss-vulnerability","description":"<p>WordPress Popup Maker Plugin <= 1.20.2 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Popup Maker<\/p><p>Fixed in version 1.20.3 <\/p><p>Affected Version <= 1.20.2<\/p><p>CVE: CVE-2025-24746<\/p>","date":"2025-01-24"},{"id":"029564e137e7ebc7f0eae6c689533ad424d8ea00","name":"Popup Maker <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1202-authenticated-contributor-stored-cross-site-scripting","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-01-24"},{"id":"EUVD-2025-3935","name":"EUVD-2025-3935","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-3935","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker allows Stored XSS. This issue affects Popup Maker: from n\/a through 1.20.2.","date":"2025-01-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"89ffeefb7ba4fa2ae693f665525975aa0e5931564d62c7bfcc00fc9cd3e80b95","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.20.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-4205","name":"Popup Maker <= 1.20.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via popupID Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-4205","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"6249b7d6794a78c2e2a55a6f3e0abc36f9314c41","name":"Popup Maker <= 1.20.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via popupID Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1204-authenticated-contributor-stored-cross-site-scripting-via-popupid-parameter","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-02"},{"id":"EUVD-2025-16719","name":"EUVD-2025-16719","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-16719","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"78699f29c1bb9bf051de5ef3d8fcbb7e68f5dec49e3de67d783ce8081b987573","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.21.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.21.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9490","name":"Popup Maker <= 1.20.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9490","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018title\u2019 parameter in all versions up to, and including, 1.20.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"EUVD-2025-31215","name":"EUVD-2025-31215","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-31215","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018title\u2019 parameter in all versions up to, and including, 1.20.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-09-26"},{"id":"52ad1dbf440add8b8130b462785e4df0c3868c33","name":"Popup Maker <= 1.20.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1206-authenticated-contributor-stored-cross-site-scripting-via-title-parameter","description":"The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018title\u2019 parameter in all versions up to, and including, 1.20.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-09-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d63abf50cfcc723d02c47acfd7f3837754adbda594b11940082901733a7658f3","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.23.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-8848","name":"CVE-2026-8848","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-8848","description":"[en] The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with editor-level access and above, to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution. Exploitation requires that a valid Popup Maker Pro license is active on the target site and that Popup Maker Pro is not yet installed, as these conditions are necessary for the legacy v1\/connect\/info endpoint to issue the bearer token used to satisfy the install endpoint's only non-spoofable validation check.","date":"2026-07-09"},{"id":"58417e679fcb86a5781807f33daed95c6af370f3","name":"Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-boost-sales-conversions-optins-subscribers-with-the-ultimate-wp-popup-builder-1220-missing-authorization-to-authenticated-editor-arbitrary-plugin-installation","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with editor-level access and above, to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution. Exploitation requires that a valid Popup Maker Pro license is active on the target site and that Popup Maker Pro is not yet installed, as these conditions are necessary for the legacy v1\/connect\/info endpoint to issue the bearer token used to satisfy the install endpoint's only non-spoofable validation check.","date":"2026-07-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"ca6781c4275760ed7dcd99c91a492f8187714c3156c13fa0a08b3268cb246a2e","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.24.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.24.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-28177","name":"CVE-2026-28177","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-28177","description":"[en] Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.","date":"2026-08-06"},{"id":"c16bf05ed3eb0af54cb3b907b72580af6438ba31","name":"Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.23.0 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-boost-sales-conversions-optins-subscribers-with-the-ultimate-wp-popup-builder-1230-unauthenticated-stored-cross-site-scripting","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.23.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-08-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e0f8ca6e9a57c2bd3d386240631693e6b9dd05e4b706696647ed6e2b9136e8b3","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.25.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.25.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-87915","name":"CVE-2026-87915","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-87915","description":"[en] The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses sanitization applied on output is insufficient in this context because HTML entities within allowed attribute values survive normalization intact and are later evaluated by the jQuery(link.attr('href')) sink in wp-admin\/js\/common.js when a contextual help tab anchor is clicked.","date":"2026-09-18"},{"id":"b4867a70d9fb0471547ccaf0e114729b7093631c","name":"Popup Maker <= 1.24.0 - Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1240-unauthenticated-stored-cross-site-scripting-via-valuesname-parameter","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses sanitization applied on output is insufficient in this context because HTML entities within allowed attribute values survive normalization intact and are later evaluated by the jQuery(link.attr('href')) sink in wp-admin\/js\/common.js when a contextual help tab anchor is clicked.","date":"2026-09-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d0c3acc0af2700662f1e73e700370a56b92134ea73ceba65b21f59d6847bb684","name":"Popup Maker &#8211; Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.25.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.25.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15797","name":"CVE-2026-15797","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15797","description":"[en] The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component.","date":"2026-09-18"},{"id":"df3f937299c0cd481cd8c00a8e646918bf626abf","name":"Popup Maker <= 1.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_title","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/popup-maker\/popup-maker-1240-authenticated-contributor-stored-cross-site-scripting-via-post-title","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component.","date":"2026-09-17"},{"id":"EUVD-2026-82854","name":"EUVD-2026-82854","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-82854","description":"The Popup Maker \u2013 Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component.","date":"2026-09-18"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.004"}}]},"updated":"1789971113"}