plugin

Cm Pop Up Banners Vulnerabilities

15 known security issues reported for the Cm Pop Up Banners WordPress plugin. Most recent disclosed Jul 16, 2025.

1 high 5 medium

Running Cm Pop Up Banners on your site? Check whether your installed version is affected.

Scan your site free

CM Pop-Up banners <= 1.8.4 - Missing Authorization

medium

The CM Pop-Up – Create engaging popups to capture attention and boost interaction plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and ab...

CVSS:
4.3
Affected:
up to 1.8.4
Fixed in:
1.8.5
Disclosed:
Jul 16, 2025

CVE-2025-54018 on NVD →

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.8.5

unknown

[en] Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CM Pop-Up banners: from n/a through 1.8.4.

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Jul 16, 2025

CVE-2025-54018 on NVD →

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.7.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.

Affected:
up to 1.7.4
Fixed in:
1.7.4
Disclosed:
Mar 3, 2025

CVE-2025-24758 on NVD →

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.7.6

unknown

[en] Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...

Affected:
up to 1.7.6
Fixed in:
1.7.6
Disclosed:
Nov 26, 2024

CVE-2024-11202 on NVD →

Multiple Plugins <= (Various Versions) - Reflected Cross-Site Scripting via cminds_free_guide Shortcode

medium

Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 1.7.5
Fixed in:
1.7.6
Disclosed:
Nov 25, 2024

CVE-2024-11202 on NVD →

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.7.3

unknown

[en] The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

Affected:
up to 1.7.3
Fixed in:
1.7.3
Disclosed:
Sep 12, 2024

CVE-2024-5799 on NVD →

CM Pop-Up Banners <= 1.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The CM Pop-Up Banners for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via campaign data in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to...

CVSS:
6.4
Affected:
up to 1.7.2
Fixed in:
1.7.3
Disclosed:
Aug 22, 2024

CVE-2024-5799 on NVD →

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.6.6

unknown

[en] The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Jul 22, 2024

CVE-2024-5004 on NVD →

CM Popup Plugin for WordPress – Popup Maker <= 1.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The CM Popup Plugin for WordPress – Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width value in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.4
Affected:
up to 1.6.5
Fixed in:
1.6.6
Disclosed:
Jul 1, 2024

CVE-2024-5004 on NVD →

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.6.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Dec 20, 2023

CVE-2023-30750 on NVD →

CM Pop-Up banners <= 1.5.10 - Authenticated (Subscriber+) SQL Injection via getStatistics

high

The CM Pop-Up banners plugin for WordPress is vulnerable to generic SQL Injection via the getStatistics function in versions up to, and including, 1.5.10 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...

CVSS:
8.8
Affected:
up to 1.5.10
Fixed in:
1.6.0
Disclosed:
May 3, 2023

CVE-2023-30750 on NVD →

CM Pop-Up banners <= 1.4.10 - Authenticated Stored Cross-Site Scripting

medium

The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...

CVSS:
6.4
Affected:
up to 1.4.10
Fixed in:
1.5.0
Disclosed:
Mar 27, 2020

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Jeroen Mulder in WordPress CM Pop-Up banners plugin (versions <= 1.4.10).

Affected:
up to 1.4.11
Fixed in:
1.4.11
Disclosed:
Mar 27, 2020

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.5.0

unknown

The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...

Affected:
up to 1.5.0
Fixed in:
1.5.0
Disclosed:
Mar 27, 2020

CM Pop-Up &#8211; Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11

unknown

When saving a new campaign, a user with edit_pages capabilities can store scripts in the campaign&rsquo;s pop-up content. The code can then be executed on every page on the website.

Affected:
up to 1.4.11
Fixed in:
1.4.11

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database