cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forpopup-maker popup-maker

Direction: descending
Jun 06, 2025

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2025-4205

CVE, Research URL

CVE-2025-4205

Date
Jun 03, 2025
Research Description
The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘popupID' parameter in all versions up to, and including, 1.20.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jan 25, 2025

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2025-24746

CVE, Research URL

CVE-2025-24746

Date
Jan 24, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker allows Stored XSS. This issue affects Popup Maker: from n/a through 1.20.2.
Affected versions
Min -, max -.
Status
vulnerable
Dec 12, 2024

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2024-10583

CVE, Research URL

CVE-2024-10583

Date
Dec 12, 2024
Research Description
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Oct 03, 2024

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2024-47358

CVE, Research URL

CVE-2024-47358

Date
Nov 01, 2024
Research Description
Missing Authorization vulnerability in Popup Maker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Popup Maker: from n/a through 1.19.2.
Affected versions
Min -, max -.
Status
vulnerable
Sep 11, 2024

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2024-5561

CVE, Research URL

CVE-2024-5561

Date
Sep 09, 2024
Research Description
The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Affected versions
Min -, max -.
Status
vulnerable
Aug 20, 2024

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2024-7054

CVE, Research URL

CVE-2024-7054

Date
Aug 20, 2024
Research Description
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2022-45819

CVE, Research URL

CVE-2022-45819

Date
Dec 13, 2024
Research Description
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.
Affected versions
Min -, max -.
Status
vulnerable
Jun 07, 2024

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2022-3690

CVE, Research URL

CVE-2022-3690

Date
Nov 21, 2022
Research Description
The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins
Affected versions
Min -, max -.
Status
vulnerable

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2022-1104

CVE, Research URL

CVE-2022-1104

Date
May 09, 2022
Research Description
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Affected versions
Min -, max -.
Status
vulnerable

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2022-4362

CVE, Research URL

CVE-2022-4362

Date
Jan 03, 2023
Research Description
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2017-2284

CVE, Research URL

CVE-2017-2284

Date
Aug 02, 2017
Research Description
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
Min -, max -.
Status
vulnerable

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2019-17574

CVE, Research URL

CVE-2019-17574

Date
Oct 14, 2019
Research Description
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
Affected versions
Min -, max -.
Status
vulnerable

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2022-4381

CVE, Research URL

CVE-2022-4381

Date
Jan 03, 2023
Research Description
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Affected versions
Min -, max -.
Status
vulnerable

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2022-47597

CVE, Research URL

CVE-2022-47597

Date
Dec 20, 2023
Research Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Popup Maker Popup Maker – Popup for opt-ins, lead gen, & more.This issue affects Popup Maker – Popup for opt-ins, lead gen, & more: from n/a through 1.17.1.
Affected versions
Min -, max -.
Status
vulnerable

Popup Maker – Popup for opt-ins, lead gen, & more # CVE-2024-2336

CVE, Research URL

CVE-2024-2336

Date
Apr 10, 2024
Research Description
The Popup Maker – Popup for opt-ins, lead gen, & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.18.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable