cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcm-pop-up-banners cm-pop-up-banners

Direction: descending
Jul 19, 2025

CM Popup Plugin for WordPress – Popup Maker # CVE-2025-54018

CVE, Research URL

CVE-2025-54018

Date
Jul 16, 2025
Research Description
Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CM Pop-Up banners: from n/a through 1.8.4.
Affected versions
Min -, max -.
Status
vulnerable
Feb 19, 2025

CM Popup Plugin for WordPress – Popup Maker # CVE-2025-24758

CVE, Research URL

CVE-2025-24758

Date
Mar 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
Affected versions
Min -, max -.
Status
vulnerable
Nov 27, 2024

CM Popup Plugin for WordPress – Popup Maker # CVE-2024-11202

CVE, Research URL

CVE-2024-11202

Date
Nov 26, 2024
Research Description
CM Popup Plugin for WordPress &#8211; Popup Maker [cm-pop-up-banners] < 1.7.6 CVE-2024-11202 [en] Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
Min -, max -.
Status
vulnerable
Sep 14, 2024

CM Popup Plugin for WordPress &#8211; Popup Maker # CVE-2024-5799

CVE, Research URL

CVE-2024-5799

Date
Sep 12, 2024
Research Description
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
Affected versions
Min -, max -.
Status
vulnerable
Jun 06, 2024

CM Popup Plugin for WordPress &#8211; Popup Maker # CVE-2023-30750

CVE, Research URL

CVE-2023-30750

Date
Dec 20, 2023
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.
Affected versions
Min -, max -.
Status
vulnerable

CM Popup Plugin for WordPress &#8211; Popup Maker # bd83e4633dafac3814d85f28a03f71003eba1259

Date
Mar 27, 2020
Research Description
CM Popup Plugin for WordPress &#8211; Popup Maker [cm-pop-up-banners] < 1.5.0 WordPress CM Pop-Up banners plugin <= 1.4.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Jeroen Mulder in WordPress CM Pop-Up banners plugin (versions <= 1.4.10).
Affected versions
Min -, max -.
Status
vulnerable