Vulnerabilities and security researches forcm-pop-up-banners cm-pop-up-banners
Direction: descendingJul 19, 2025
CM Popup Plugin for WordPress – Popup Maker # CVE-2025-54018
- CVE, Research URL
- Date
- Jul 16, 2025
- Research Description
- Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CM Pop-Up banners: from n/a through 1.8.4.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Feb 19, 2025
CM Popup Plugin for WordPress – Popup Maker # CVE-2025-24758
- CVE, Research URL
- Date
- Mar 03, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Nov 27, 2024
CM Popup Plugin for WordPress – Popup Maker # CVE-2024-11202
- CVE, Research URL
- Date
- Nov 26, 2024
- Research Description
- CM Popup Plugin for WordPress – Popup Maker [cm-pop-up-banners] < 1.7.6 CVE-2024-11202 [en] Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Sep 14, 2024
CM Popup Plugin for WordPress – Popup Maker # CVE-2024-5799
- CVE, Research URL
- Date
- Sep 12, 2024
- Research Description
- The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 06, 2024
CM Popup Plugin for WordPress – Popup Maker # CVE-2023-30750
- CVE, Research URL
- Date
- Dec 20, 2023
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
CM Popup Plugin for WordPress – Popup Maker # bd83e4633dafac3814d85f28a03f71003eba1259
- CVE, Research URL
- Date
- Mar 27, 2020
- Research Description
- CM Popup Plugin for WordPress – Popup Maker [cm-pop-up-banners] < 1.5.0 WordPress CM Pop-Up banners plugin <= 1.4.10 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Jeroen Mulder in WordPress CM Pop-Up banners plugin (versions <= 1.4.10).
- Affected versions
-
Min -, max -.
- Status
-
vulnerable