Vulnerabilities and security researches forcm-pop-up-banners cm-pop-up-banners
Direction: ascendingJun 06, 2024
CM Popup Plugin for WordPress – Popup Maker # CVE-2023-30750
- CVE, Research URL
- Date
- Dec 20, 2023
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.
- Affected versions
-
max 1.6.0.
- Status
-
vulnerable
CM Popup Plugin for WordPress – Popup Maker # bd83e4633dafac3814d85f28a03f71003eba1259
- CVE, Research URL
- Date
- Mar 27, 2020
- Research Description
- CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11 WordPress CM Pop-Up banners plugin <= 1.4.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Jeroen Mulder in WordPress CM Pop-Up banners plugin (versions <= 1.4.10).
- Affected versions
-
max 1.4.11.
- Status
-
vulnerable
Sep 14, 2024
CM Popup Plugin for WordPress – Popup Maker # CVE-2024-5799
- CVE, Research URL
- Date
- Sep 12, 2024
- Research Description
- The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
- Affected versions
-
max 1.7.3.
- Status
-
vulnerable
Nov 27, 2024
CM Popup Plugin for WordPress – Popup Maker # CVE-2024-11202
- CVE, Research URL
- Date
- Nov 26, 2024
- Research Description
- Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.7.6.
- Status
-
vulnerable
Feb 19, 2025
CM Popup Plugin for WordPress – Popup Maker # CVE-2025-24758
- CVE, Research URL
- Date
- Mar 03, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations cm-map-locations allows Reflected XSS.This issue affects CM Map Locations: from n/a through <= 2.0.8.
- Affected versions
-
max 1.7.4.
- Status
-
vulnerable
Jul 19, 2025
CM Popup Plugin for WordPress – Popup Maker # CVE-2025-54018
- CVE, Research URL
- Date
- Jul 16, 2025
- Research Description
- Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners cm-pop-up-banners allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM Pop-Up banners: from n/a through <= 1.8.4.
- Affected versions
-
max 1.8.5.
- Status
-
vulnerable
Jun 14, 2026
CM Popup Plugin for WordPress – Popup Maker # CVE-2024-5004
- CVE, Research URL
- Date
- Jul 22, 2024
- Research Description
- The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
- Affected versions
-
max 1.6.6.
- Status
-
vulnerable
Jun 16, 2026
CM Popup Plugin for WordPress – Popup Maker # b9d2f603-fd4a-4028-9799-7a88f2ce279c
- CVE, Research URL
- Date
- -
- Research Description
- CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11 CM Pop-Up banners < 1.4.11 - Authenticated Stored XSS When saving a new campaign, a user with edit_pages capabilities can store scripts in the campaign’s pop-up content. The code can then be executed on every page on the website.
- Affected versions
-
max 1.4.11.
- Status
-
vulnerable
CM Popup Plugin for WordPress – Popup Maker # af27a597e9f76b8af9997983efa52ec0ea31db03
- CVE, Research URL
- Date
- Mar 27, 2020
- Research Description
- CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.5.0 CM Pop-Up banners <= 1.4.10 - Authenticated Stored Cross-Site Scripting The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.5.0.
- Status
-
vulnerable