Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-47358

Disclosure Date: November 01, 2024 (last updated November 13, 2024)
Missing Authorization vulnerability in Popup Maker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Popup Maker: from n/a through 1.19.2.
Attacker Value
Unknown

CVE-2024-5561

Disclosure Date: September 09, 2024 (last updated October 08, 2024)
The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2022-47597

Disclosure Date: December 20, 2023 (last updated December 28, 2023)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Popup Maker Popup Maker – Popup for opt-ins, lead gen, & more.This issue affects Popup Maker – Popup for opt-ins, lead gen, & more: from n/a through 1.17.1.
Attacker Value
Unknown

CVE-2022-4509

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Content Control WordPress plugin before 1.1.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4381

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-4362

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Popup Maker WordPress plugin before 1.16.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-3690

Disclosure Date: November 21, 2022 (last updated November 08, 2023)
The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins
Attacker Value
Unknown

CVE-2022-1104

Disclosure Date: May 09, 2022 (last updated October 07, 2023)
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2019-17574

Disclosure Date: October 14, 2019 (last updated November 27, 2024)
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
Attacker Value
Unknown

CVE-2017-2284

Disclosure Date: August 02, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0