cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpopup-maker-wp popup-maker-wp

Direction: ascending
Jun 07, 2024

Popup Maker – Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder & More # CVE-2024-34770

CVE, Research URL

CVE-2024-34770

Date
Jun 03, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker WP popup-maker-wp allows Stored XSS.This issue affects Popup Maker WP: from n/a through <= 1.3.6.
Affected versions
max 1.3.7.
Status
vulnerable
Oct 04, 2026

Popup Maker &#8211; Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder &amp; More # CVE-2026-85004

CVE, Research URL

CVE-2026-85004

Date
Oct 02, 2026
Research Description
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.
Affected versions
max 1.4.5.
Status
vulnerable

Popup Maker &#8211; Responsive popup, Exit Intent Pop up, Email Optins, Autoresponder &amp; More # CVE-2026-85005

CVE, Research URL

CVE-2026-85005

Date
Oct 02, 2026
Research Description
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
Affected versions
max 1.4.5.
Status
vulnerable