cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcm-pop-up-banners cm-pop-up-banners

Direction: ascending
Jun 06, 2024

CM Popup Plugin for WordPress – Popup Maker # CVE-2023-30750

CVE, Research URL

CVE-2023-30750

Date
Dec 20, 2023
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.
Affected versions
max 1.6.0.
Status
vulnerable

CM Popup Plugin for WordPress – Popup Maker # bd83e4633dafac3814d85f28a03f71003eba1259

Date
Mar 27, 2020
Research Description
CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11 WordPress CM Pop-Up banners plugin <= 1.4.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Jeroen Mulder in WordPress CM Pop-Up banners plugin (versions <= 1.4.10).
Affected versions
max 1.4.11.
Status
vulnerable
Sep 14, 2024

CM Popup Plugin for WordPress &#8211; Popup Maker # CVE-2024-5799

CVE, Research URL

CVE-2024-5799

Date
Sep 12, 2024
Research Description
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
Affected versions
max 1.7.3.
Status
vulnerable
Nov 27, 2024

CM Popup Plugin for WordPress &#8211; Popup Maker # CVE-2024-11202

CVE, Research URL

CVE-2024-11202

Date
Nov 26, 2024
Research Description
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.7.6.
Status
vulnerable
Feb 19, 2025

CM Popup Plugin for WordPress &#8211; Popup Maker # CVE-2025-24758

CVE, Research URL

CVE-2025-24758

Date
Mar 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations cm-map-locations allows Reflected XSS.This issue affects CM Map Locations: from n/a through <= 2.0.8.
Affected versions
max 1.7.4.
Status
vulnerable
Jul 19, 2025

CM Popup Plugin for WordPress &#8211; Popup Maker # CVE-2025-54018

CVE, Research URL

CVE-2025-54018

Date
Jul 16, 2025
Research Description
Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners cm-pop-up-banners allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM Pop-Up banners: from n/a through <= 1.8.4.
Affected versions
max 1.8.5.
Status
vulnerable
Jun 14, 2026

CM Popup Plugin for WordPress &#8211; Popup Maker # CVE-2024-5004

CVE, Research URL

CVE-2024-5004

Date
Jul 22, 2024
Research Description
The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
Affected versions
max 1.6.6.
Status
vulnerable
Jun 16, 2026

CM Popup Plugin for WordPress &#8211; Popup Maker # b9d2f603-fd4a-4028-9799-7a88f2ce279c

Date
-
Research Description
CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11 CM Pop-Up banners &lt; 1.4.11 - Authenticated Stored XSS When saving a new campaign, a user with edit_pages capabilities can store scripts in the campaign&rsquo;s pop-up content. The code can then be executed on every page on the website.
Affected versions
max 1.4.11.
Status
vulnerable

CM Popup Plugin for WordPress &#8211; Popup Maker # af27a597e9f76b8af9997983efa52ec0ea31db03

Date
Mar 27, 2020
Research Description
CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.5.0 CM Pop-Up banners <= 1.4.10 - Authenticated Stored Cross-Site Scripting The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.5.0.
Status
vulnerable